Extension WordPress
Vulnérabilités WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN)
Cette page rassemble les failles publiées pour WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN), leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN)
4 fiches
WPO365 <= 40.0 – Authenticated (Subscriber+) Server-Side Request Forgery
The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 40.0. This makes it possible for authenticated attackers, with Subscriber-level access…
*-40.0
40.1
21/01/2026
WordPress + Microsoft Office 365 / Azure AD | LOGIN <= 27.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via pintra Shortcode
The WordPress + Microsoft Office 365 / Azure AD | LOGIN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pintra' shortcode in all versions up to, and including, 27.2 due to insufficient input sanitization…
*-27.2
28.0
22/05/2024
WordPress + Microsoft Office 365 / Azure AD | LOGIN <= 15.3 – Stored Cross-Site Scripting
The WPO365 | LOGIN WordPress plugin (up to and including version 15.3) by wpo365.com is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Second-Order XSS). Persistent XSS vulnerabilities occur when the application stores…
*-15.3
15.4
15/10/2021
WPO365 | LOGIN <= 11.6 – Authentication Bypass
The WPO365 | LOGIN plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This leads to authentication bypass.
*-11.6
11.7
02/10/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.