Authentication Bypass via OIDC Nonce Replay in WPO365 Login Plugin
An authentication bypass vulnerability in the WPO365 Login plugin allows unauthenticated attackers to hijack user sessions by replaying previously issued OIDC tokens.
CVE search metadata
CVE search record: CVE-2026-104759. Severity: high. CVSS: 8.1. KEV: no. Product: WPO365 | LOGIN (<= 44.1). Brief: Authentication Bypass via OIDC Nonce Replay in WPO365 Login Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-wpo365-auth-bypass/
The WPO365 | LOGIN plugin for WordPress (versions 44.1 and earlier) contains a critical authentication bypass vulnerability identified as CVE-2026-104759. The flaw originates in the Id_Token_Service_Deprecated::process_openidconnect_token() method, which improperly uses the WordPress core wp_verify_nonce() function to validate security tokens. Because wp_verify_nonce() is incompatible with the 64-character hex nonces generated by the Nonce_Service::create_nonce() function, the validation check fails silently. This failure does not terminate the authentication process, allowing the plugin to proceed to authenticate_oidc_user() using an attacker-supplied id_token.
This vulnerability is active specifically when the use_id_token_parser_v2 option is enabled in the plugin settings. An attacker who obtains a valid id_token for a target account can replay that token to impersonate any user on the system, including administrators. Successful exploitation leads to full site takeover, as the application incorrectly grants access based on the replayed token without validating the nonce session state.
Impact
Successful exploitation of this vulnerability allows unauthenticated attackers to achieve full site takeover by bypassing OIDC authentication. This impacts the confidentiality, integrity, and availability of any WordPress installation utilizing the vulnerable plugin configuration, as attackers can gain administrative privileges to modify site content, exfiltrate user data, or inject malicious scripts.
Recommendation
- Update the WPO365 | LOGIN plugin to the latest version immediately to remediate CVE-2026-104759.
- If patching is not immediately feasible, disable the
use_id_token_parser_v2option in the plugin configuration to prevent the use of the vulnerable deprecated token parser. - Audit web server logs for unexpected POST requests to WordPress OIDC authentication endpoints that lack corresponding original session initiation requests.
Immediate actions
Update WPO365 | LOGIN plugin to the latest patched version
Mitigations
Disable use_id_token_parser_v2 option in plugin settings
CVE-2026-104759