PT-2026-64159 · Wpo365 · Wpo365 | Seamless Wordpress + Microsoft Integration
CVE-2026-15212
·
Publicado
2026-07-23
·
Atualizado
2026-07-23
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax Service::verify ajax request() helper gating its wp verify nonce() call behind the boolean option 'enable nonce check', which is absent from the default 'wpo365 options' array and therefore evaluates to false via get global boolean var(); as a result, the wp ajax wpo365 update settings handler (Ajax Service::update settings) accepts POSTs from cross-origin pages and forwards the attacker-supplied 'settings' payload (base64/JSON) to Options Service::update options(), which merges every key/value into wpo365 options without a key allowlist. This makes it possible for unauthenticated attackers to overwrite arbitrary plugin options — including enabling the SCIM REST endpoint (enable scim), planting an attacker-known scim secret token, and setting new usr default role to 'administrator' — via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wpo365 | Seamless Wordpress + Microsoft Integration