CVE-2026-104759: WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Unauthenticated Authentication Bypass via OIDC Nonce Replay via id_token Nonce Verification

Published Oct 10, 2026
·
Updated

The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Authentication Bypass via OIDC Nonce Replay in all versions up to, and including, 44.1 This is due to IdTokenServiceDeprecated::processopenidconnecttoken() using the incompatible WordPress core wpverifynonce() function to validate a nonce produced by NonceService::createnonce() — a 64-character hex value that wpverifynonce() can never successfully verify — causing the nonce check to silently fail without terminating authentication, so execution continues into authenticateoidcuser() with the attacker-supplied idtoken. This makes it possible for unauthenticated attackers who have obtained a previously-issued, valid idtoken for a target account to replay that token and authenticate as any WordPress user, including administrators, resulting in full site takeover. This vulnerability is only exploitable when the useidtokenparserv2 plugin option is enabled, as this is the configuration that routes token processing through the deprecated parser containing the broken nonce check.

Affected Software

1 affected component
WPO365 WPO365 | LOGIN<=44.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Disable the use_id_token_parser_v2 plugin option to prevent token processing from using the deprecated parser with the broken nonce check.

    WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) use_id_token_parser_v2 = false

Event History

Oct 10, 2026
CVE Published
via MITRE·07:41 AM
Data Sourced
via MITRE·07:41 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to exploitation?

Deployments running WPO365 | LOGIN version 44.1 or earlier are exposed only if the use_id_token_parser_v2 plugin option is enabled. That setting routes OIDC token handling through the deprecated parser with the failed nonce validation.

2

What does an attacker need to exploit this issue?

An unauthenticated attacker needs a previously issued, valid id_token for the WordPress account they want to impersonate. They can replay that token to authenticate as that user, including an administrator.

3

Is the vulnerable behavior enabled by default?

The available data does not state the default value of use_id_token_parser_v2. Exploitability depends on whether that option is enabled in the affected deployment.

4

How can I determine whether my site is affected?

Check whether the site uses WPO365 | LOGIN version 44.1 or earlier and whether its use_id_token_parser_v2 option is enabled. Both conditions must be present for the described exploit path.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203