Sceawere
Vulnerability Detail
CVE-2026-96765UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WPO365 Stored XSS Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 2h ago
- Vendor
- wpo365
- Product
- WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN)
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id_token' parameter in all versions up to, and including, 44.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is stored in the wpo365_errors transient for up to three days by submitting a crafted unauthenticated request with a forged id_token whose base64url-decoded unique_name or iss claim contains malicious HTML, requiring no prior authentication or user interaction beyond an administrator later visiting the WPO365 wizard page.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-10T08:17:08.170Z",
"pubdate": "2026-10-10T08:17:08.170Z",
"executiveSummary": "The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION plugin is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability, classified as a security flaw in input sanitization and output escaping. This vulnerability affects all versions up to and including 44.1. An unauthenticated attacker can exploit this by injecting malicious scripts into the 'id_token' parameter, which are subsequently stored in the 'wpo365_errors' transient. The payload remains resident for up to three days. The primary impact involves the execution of arbitrary JavaScript within the context of the administrator's browser when they access the WPO365 wizard page. This allows for unauthorized actions, session hijacking, or the modification of site configurations. Successful exploitation does not require prior authentication, making it a critical threat to the integrity of the WordPress site. The attack relies on a forged JWT claim processed by the plugin without sufficient validation, creating a significant security exposure.",
"technicalDetails": "The vulnerability resides within the authentication flow of the WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION plugin, specifically concerning how the 'id_token' parameter is processed. The plugin fails to adequately sanitize the 'unique_name' or 'iss' claims contained within the base64url-encoded JSON Web Token (JWT).\nWhen an attacker crafts a malicious request containing a forged 'id_token', the plugin extracts the payload from these claims and stores the data into the 'wpo365_errors' transient. Because this storage mechanism persists for up to three days, it creates a staging area for the malicious payload. The vulnerability is triggered when an administrative user navigates to the WPO365 wizard page, where the plugin attempts to render the previously stored error information.\nThe root cause is the lack of proper output escaping on the administrative interface. The application reflects the unsanitized contents of the 'wpo365_errors' transient directly into the HTML output. Consequently, the browser interprets the injected JavaScript as legitimate code rather than data, leading to the execution of the attacker's payload.\nAttack Flow: 1. Attacker crafts a base64url-encoded payload embedded within the 'unique_name' or 'iss' claim of a JWT. 2. Attacker submits an unauthenticated request to the plugin containing the forged 'id_token'. 3. The plugin processes the JWT and writes the malicious content into the 'wpo365_errors' transient. 4. An administrator visits the WPO365 wizard page. 5. The plugin retrieves the transient and renders it in the administrative dashboard. 6. The victim's browser executes the script, facilitating post-exploitation activities such as cross-site request forgery, data theft, or privilege escalation.\nAffected Versions: All versions up to, and including, 44.1. The vulnerability is accessible via the network without requiring any specific user interaction or authentication credentials, posing a high risk to administrative security."
}