{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awpo365login/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wpo365:login:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-104759"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WPO365 | LOGIN (\u003c= 44.1)"],"_cs_severities":["high"],"_cs_tags":["wordpress","authentication-bypass","cve-2026-104759"],"_cs_type":"advisory","_cs_vendors":["WPO365"],"content_html":"\u003cp\u003eThe WPO365 | LOGIN plugin for WordPress (versions 44.1 and earlier) contains a critical authentication bypass vulnerability identified as CVE-2026-104759. The flaw originates in the \u003ccode\u003eId_Token_Service_Deprecated::process_openidconnect_token()\u003c/code\u003e method, which improperly uses the WordPress core \u003ccode\u003ewp_verify_nonce()\u003c/code\u003e function to validate security tokens. Because \u003ccode\u003ewp_verify_nonce()\u003c/code\u003e is incompatible with the 64-character hex nonces generated by the \u003ccode\u003eNonce_Service::create_nonce()\u003c/code\u003e function, the validation check fails silently. This failure does not terminate the authentication process, allowing the plugin to proceed to \u003ccode\u003eauthenticate_oidc_user()\u003c/code\u003e using an attacker-supplied \u003ccode\u003eid_token\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eThis vulnerability is active specifically when the \u003ccode\u003euse_id_token_parser_v2\u003c/code\u003e option is enabled in the plugin settings. An attacker who obtains a valid \u003ccode\u003eid_token\u003c/code\u003e for a target account can replay that token to impersonate any user on the system, including administrators. Successful exploitation leads to full site takeover, as the application incorrectly grants access based on the replayed token without validating the nonce session state.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated attackers to achieve full site takeover by bypassing OIDC authentication. This impacts the confidentiality, integrity, and availability of any WordPress installation utilizing the vulnerable plugin configuration, as attackers can gain administrative privileges to modify site content, exfiltrate user data, or inject malicious scripts.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the WPO365 | LOGIN plugin to the latest version immediately to remediate CVE-2026-104759.\u003c/li\u003e\n\u003cli\u003eIf patching is not immediately feasible, disable the \u003ccode\u003euse_id_token_parser_v2\u003c/code\u003e option in the plugin configuration to prevent the use of the vulnerable deprecated token parser.\u003c/li\u003e\n\u003cli\u003eAudit web server logs for unexpected POST requests to WordPress OIDC authentication endpoints that lack corresponding original session initiation requests.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T09:51:34Z","date_published":"2026-10-10T09:51:34Z","id":"https://feed.craftedsignal.io/briefs/2026-10-wpo365-auth-bypass/","summary":"An authentication bypass vulnerability in the WPO365 Login plugin allows unauthenticated attackers to hijack user sessions by replaying previously issued OIDC tokens.","title":"Authentication Bypass via OIDC Nonce Replay in WPO365 Login Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-wpo365-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wpo365:login:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}