<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>WPO365 | LOGIN (&lt;= 44.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/wpo365--login--44.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 09:51:34 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/wpo365--login--44.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass via OIDC Nonce Replay in WPO365 Login Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-wpo365-auth-bypass/</link><pubDate>Sat, 10 Oct 2026 09:51:34 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-wpo365-auth-bypass/</guid><description>An authentication bypass vulnerability in the WPO365 Login plugin allows unauthenticated attackers to hijack user sessions by replaying previously issued OIDC tokens.</description><content:encoded><![CDATA[<p>The WPO365 | LOGIN plugin for WordPress (versions 44.1 and earlier) contains a critical authentication bypass vulnerability identified as CVE-2026-104759. The flaw originates in the <code>Id_Token_Service_Deprecated::process_openidconnect_token()</code> method, which improperly uses the WordPress core <code>wp_verify_nonce()</code> function to validate security tokens. Because <code>wp_verify_nonce()</code> is incompatible with the 64-character hex nonces generated by the <code>Nonce_Service::create_nonce()</code> function, the validation check fails silently. This failure does not terminate the authentication process, allowing the plugin to proceed to <code>authenticate_oidc_user()</code> using an attacker-supplied <code>id_token</code>.</p>
<p>This vulnerability is active specifically when the <code>use_id_token_parser_v2</code> option is enabled in the plugin settings. An attacker who obtains a valid <code>id_token</code> for a target account can replay that token to impersonate any user on the system, including administrators. Successful exploitation leads to full site takeover, as the application incorrectly grants access based on the replayed token without validating the nonce session state.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthenticated attackers to achieve full site takeover by bypassing OIDC authentication. This impacts the confidentiality, integrity, and availability of any WordPress installation utilizing the vulnerable plugin configuration, as attackers can gain administrative privileges to modify site content, exfiltrate user data, or inject malicious scripts.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the WPO365 | LOGIN plugin to the latest version immediately to remediate CVE-2026-104759.</li>
<li>If patching is not immediately feasible, disable the <code>use_id_token_parser_v2</code> option in the plugin configuration to prevent the use of the vulnerable deprecated token parser.</li>
<li>Audit web server logs for unexpected POST requests to WordPress OIDC authentication endpoints that lack corresponding original session initiation requests.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>authentication-bypass</category><category>cve-2026-104759</category></item></channel></rss>