CVE-2026-104759
Last modified
CVE-2026-104759 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Authentication Bypass via OIDC Nonce Replay in all versions up to, and including, 44.1 This is due to `Id_Token_Service_Deprecated::process_openidconnect_token()` using the incompatible WordPress core `wp_verify_nonce()` function to validate a nonce produced by `Nonce_Service::create_nonce()` — a 64-character hex value that `wp_verify_nonce()` can never successfully verify — causing the nonce check to silently fail without terminating authentication, so execution continues into `authenticate_oidc_user()` with the attacker-supplied `id_token`. This makes it possible for unauthenticated attackers who have obtained a previously-issued, valid `id_token` for a target account to replay that token and authenticate as any WordPress user, including administrators, resulting in full site takeover.
Description
The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Authentication Bypass via OIDC Nonce Replay in all versions up to, and including, 44.1 This is due to `Id_Token_Service_Deprecated::process_openidconnect_token()` using the incompatible WordPress core `wp_verify_nonce()` function to validate a nonce produced by `Nonce_Service::create_nonce()` — a 64-character hex value that `wp_verify_nonce()` can never successfully verify — causing the nonce check to silently fail without terminating authentication, so execution continues into `authenticate_oidc_user()` with the attacker-supplied `id_token`. This makes it possible for unauthenticated attackers who have obtained a previously-issued, valid `id_token` for a target account to replay that token and authenticate as any WordPress user, including administrators, resulting in full site takeover. This vulnerability is only exploitable when the `use_id_token_parser_v2` plugin option is enabled, as this is the configuration that routes token processing through the deprecated parser containing the broken nonce check.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| wpo365 | WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) | <= 44.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-104759?
How severe is CVE-2026-104759?
How do I fix CVE-2026-104759?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-104747Unauthenticated PHP Object Injection in Haaken <= 1.5 versio…8.1
- CVE-2026-104752The Rank Math SEO WordPress plugin before 1.0.280 does not …
- CVE-2026-104753The Rank Math SEO WordPress plugin before 1.0.280 does not …
- CVE-2026-104754The Rank Math SEO WordPress plugin before 1.0.280 does not …
- CVE-2026-104757Editor Privilege Escalation in Import and export users and c…7.2
- CVE-2026-104758Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-104762The Kadence Blocks — Page Builder Toolkit for Gutenberg Edit…6.4
- CVE-2026-104763The Post Export Import with Media plugin for WordPress is vu…4.9
- CVE-2026-104766The Appointment Booking Plugin – LatePoint | Calendar & Sche…8.8
- CVE-2026-104797The Advanced Form Integration — Connect Forms to 300+ Apps p…8.1
- CVE-2026-1048A weakness has been identified in LigeroSmart up to 6.1.26. …5.4
- CVE-2026-104801The PPOM – Product Addons & Custom Fields for WooCommerce pl…9.1
Are you affected by CVE-2026-104759?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
