Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

WPO365 — Vulnerabilities & Security Advisories 6

Browse all 6 CVE security advisories affecting WPO365. AI-powered Chinese analysis, POCs, and references for each vulnerability.

WPO365 serves as a security plugin for Microsoft 365 environments, enhancing protection against data breaches and compliance risks. Historically, vulnerabilities have included cross-site scripting (XSS), remote code execution (RCE), and privilege escalation flaws, often stemming from improper input validation and access control issues. The product has addressed three CVEs to date, with notable incidents involving insecure default configurations that could allow unauthorized access. WPO365's security posture emphasizes granular permission controls and encryption, though its effectiveness depends on proper implementation and ongoing maintenance. Organizations should prioritize regular updates and configuration reviews to mitigate potential risks associated with its deployment.

CVE ID Title CVSS Severity Published
CVE-2026-104759 WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Unauthenticated Authentication Bypass via OIDC Nonce Replay via id_token Nonce Verification — WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) CWE-287 8.1 High 2026-10-10
CVE-2026-96765 WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Unauthenticated Stored Cross-Site Scripting via 'id_token' Parameter (iss / unique_name JWT claims) — WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) CWE-79 7.2 High 2026-10-10
CVE-2026-15212 WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 43.2 - Cross-Site Request Forgery to Privilege Escalation via Plugin Settings Update — WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) CWE-352 8.8 High 2026-07-23
CVE-2025-1488 WPO365 | MICROSOFT 365 GRAPH MAILER <= 3.2 - Open Redirect via 'redirect_to' Parameter — WPO365 | MICROSOFT 365 GRAPH MAILER CWE-601 4.7 Medium 2025-02-24
CVE-2024-4706 WordPress + Microsoft Office 365 / Azure AD | LOGIN <= 27.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via pintra Shortcode — WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) CWE-79 6.4 Medium 2024-05-23
CVE-2023-32119 WordPress WPO365 | Mail Integration for Office 365 / Outlook Plugin <= 1.9.0 is vulnerable to Cross Site Scripting (XSS) — WPO365 | Mail Integration for Office 365 / Outlook CWE-79 5.8 Medium 2023-08-23

This page lists every published CVE security advisory associated with WPO365. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.