← WordPress Vulnerabilities
WordPress security by component

WPO365 | Login

WPO365 | Login is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Jul 23, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: wpo365-login

CVE-2026-15212: WPO365 settings CSRF can establish an administrator provisioning path

WPO365 | Login through 43.2 exposes the authenticated wpo365_update_settings AJAX action to CSRF because Ajax_Service::verify_ajax_request() checks its nonce only when the normally absent enable_nonce_check option is true. A forged base64-encoded JSON settings value is merged into wpo365_options without a key allowlist, so an attacker who induces an administrator to submit the request can enable SCIM, choose the SCIM secret and set newly provisioned users to the administrator role.

PublishedJul 23, 2026
Known safe version43.3
Safe version
Jul 23, 2026 CVE-2026-15212
WPO365 settings CSRF can establish an administrator provisioning path
WPO365 | Login through 43.2 exposes the authenticated wpo365_update_settings AJAX action to CSRF because Ajax_Service::verify_ajax_request() checks its nonce only when the normally absent enable_nonce_check option is true. A forged base64-encoded JSON settings value is merged into wpo365_options without a key allowlist, so an attacker who induces an administrator to submit the request can enable SCIM, choose the SCIM secret and set newly provisioned users to the administrator role.
43.3
CVE8.8
NVDPending
Jan 22, 2026 CVE-2025-67961
WPO365: Server-side request forgery
WPO365 is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE6.4
NVDPending
Oct 02, 2020 CVE-2020-26511
Wpo365 Login: Privilege escalation or authentication bypass
Wpo365 Login is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE7.5
NVD7.5