Sceawere
Vulnerability Detail
CVE-2026-104759UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WPO365 Authentication Bypass via Replay
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 2h ago
- Vendor
- wpo365
- Product
- WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN)
- Attack Type
- CWE-287 Improper Authentication
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Authentication Bypass via OIDC Nonce Replay in all versions up to, and including, 44.1 This is due to `Id_Token_Service_Deprecated::process_openidconnect_token()` using the incompatible WordPress core `wp_verify_nonce()` function to validate a nonce produced by `Nonce_Service::create_nonce()` — a 64-character hex value that `wp_verify_nonce()` can never successfully verify — causing the nonce check to silently fail without terminating authentication, so execution continues into `authenticate_oidc_user()` with the attacker-supplied `id_token`. This makes it possible for unauthenticated attackers who have obtained a previously-issued, valid `id_token` for a target account to replay that token and authenticate as any WordPress user, including administrators, resulting in full site takeover. This vulnerability is only exploitable when the `use_id_token_parser_v2` plugin option is enabled, as this is the configuration that routes token processing through the deprecated parser containing the broken nonce check.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-10-10T08:17:04.070Z",
"pubdate": "2026-10-10T08:17:04.070Z",
"executiveSummary": "The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION plugin, in versions up to and including 44.1, contains a critical authentication bypass vulnerability stemming from flawed OIDC nonce validation. This vulnerability allows an unauthenticated attacker to bypass security controls by replaying a previously issued, valid ID token. The flaw exists because the plugin utilizes an incompatible WordPress core function to verify custom-generated nonces, resulting in a silent failure of the security check. Consequently, the authentication process continues execution despite the failure, permitting unauthorized access to user accounts, including those with administrative privileges. Successful exploitation results in a full site takeover. This vulnerability is specifically exploitable when the 'use_id_token_parser_v2' configuration option is enabled. Given the severity of full administrative account compromise, this represents a critical risk to the confidentiality, integrity, and availability of the WordPress site. No authentication is required for the attacker to initiate the exploitation process, provided they have intercepted or obtained a valid ID token previously issued for a target account.",
"technicalDetails": "The vulnerability originates in the Id_Token_Service_Deprecated::process_openidconnect_token() method, which is responsible for handling OIDC token validation when the 'use_id_token_parser_v2' plugin option is enabled. The root cause is an architectural mismatch between the nonce creation mechanism and the verification mechanism. The plugin uses Nonce_Service::create_nonce() to generate a 64-character hexadecimal nonce for OIDC security verification; however, the validation logic erroneously invokes the WordPress core wp_verify_nonce() function to evaluate this token. The wp_verify_nonce() function is designed for specific WordPress nonces (typically a shorter, time-limited, session-bound integer-based hash) and is structurally incapable of validating the 64-character hexadecimal string generated by the plugin's service. Because wp_verify_nonce() cannot process the input, it returns false, indicating a verification failure. Crucially, the implementation does not handle this failure by terminating the authentication process. Instead, the function treats the failure as a non-fatal event, allowing the execution flow to proceed directly into authenticate_oidc_user() with the attacker-supplied id_token.\nThe attack flow proceeds as follows: An unauthenticated attacker intercepts or otherwise acquires a valid ID token that was previously issued for a target user account by the OIDC provider. Because the 'use_id_token_parser_v2' is enabled, the request containing the replayed ID token is routed through the vulnerable parser. The server invokes Id_Token_Service_Deprecated::process_openidconnect_token(), which attempts to verify the nonce. Due to the aforementioned incompatibility, the nonce check fails silently. The application logic, failing to halt the process, proceeds to authenticate the user based on the payload of the replayed ID token. Because the ID token itself is cryptographically valid (having been issued by the OIDC provider), the application proceeds to establish a session for the target account owner. This allows the attacker to impersonate any user, including administrators. The post-exploitation impact is a full site takeover, as the attacker is authenticated with the privileges associated with the ID token's subject. Since this bypass completely negates the intended nonce replay protection, the implementation is effectively rendered insecure, turning the authentication sequence into a static token acceptance mechanism."
}