PatchSiren cyber security CVE debrief
CVE-2026-96765 wpo365 CVE debrief
The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id_token' parameter in all versions up to, and including, 44.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Vendor
- wpo365
- Product
- WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN)
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
WordPress administrators and users of the WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin should be aware of this vulnerability and take necessary actions to protect their installations.
Why it matters
The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id_token' parameter in all versions up to, and including, 44.1 due to insufficient input sanitization and output escaping.
- Unauthenticated attackers can inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- This vulnerability can lead to potential security breaches and compromise of sensitive data.
- Defenders should prioritize verifying the presence of this vulnerability in their WordPress installations and updating to a patched version if available.
- Verification of the vulnerability and remediation are required.
Technical summary
The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id_token' parameter in all versions up to, and including, 44.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability has a CVSS score of 7.2 and is considered HIGH severity. Defenders should prioritize verifying the presence of this vulnerability in their WordPress installations and updating to a patched version if available.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their WordPress installations and updating to a patched version if available.
Recommended defensive actions
- Verify the presence of this vulnerability in your WordPress installations
- Update to a patched version if available
- Monitor for potential exploitation attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description, affected versions, and CVSS score of 7.2. The WPO365 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id_token' parameter. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts. The payload is stored in the wpo365_errors transient for up to three days. Defenders should verify the presence of this vulnerability in their WordPress installations and update to a patched version if The CVE
Sources and references
Verified primary and authoritative sources
-
CVE-2026-96765 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-96765
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-96765 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-96765
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Unauthenticated S
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/96xxx/CVE-2026-96765.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wpo365-login/tags/44.1/apps/dist/wizard-chunk-BpsKdXb9.js
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wpo365-login/tags/44.1/Services/Id_Token_Service.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wpo365-login/tags/44.1/Services/Log_Service.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wpo365-login/tags/44.1/Core/Script_Helpers.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wpo365-login/tags/44.1/Services/Router_Service.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wpo365-login/tags/44.1/Services/Request_Service.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/changeset/3727410/wpo365-login
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.