The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

Wordfence, Patchstack and the WPO365 vendor site confirm the 45.0 release fixes CVE-2026-96765 (stored XSS, CVSS 7.2) and related auth/token issues in versions through 44.1.

Sourcing
1source

via NVD

NVD · track record
53Stories
100%Verified
2930d
All sources →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/WPO365 plugin patches two high-severity WordPress flaws
VERIFIEDBy Xavier Rivera· ·1.5 min read

WPO365 plugin patches two high-severity WordPress flaws

The WPO365 WordPress plugin has patched two high-severity vulnerabilities in versions through 44.1. Both flaws could allow unauthenticated attackers to achieve site takeover or persistent script injection.

Source:NVD
Post
WPO365 plugin patches two high-severity WordPress flaws
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
TL;DRAI · 60 sec read

The WPO365 plugin releases fixes for two high-severity flaws affecting all versions through 44.1. CVE-2026-104759 scores 8.1 and enables full site takeover via id_token replay when a specific option is set. CVE-2026-96765 scores 7.2 and permits stored XSS in error logs. Users should update to version 45.0 to prevent attacks.

The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION plugin has received fixes for two vulnerabilities that affect all versions through 44.1.
Unauthenticated attackers who possess a previously issued valid id_token can replay it to authenticate as any WordPress user, including administrators.
Authentication bypass allows full site takeover. CVE-2026-104759 carries a CVSS score of 8.1. The flaw stems from Id_Token_Service_Deprecated::process_openidconnect_token() using the incompatible wp_verify_nonce() function to validate a nonce created by Nonce_Service::create_nonce(). The 64-character hex nonce can never be verified, so the check fails silently and execution proceeds to authenticate_oidc_user() with an attacker-supplied id_token. Unauthenticated attackers who possess a previously issued valid id_token can replay it to authenticate as any WordPress user, including administrators. The issue is exploitable only when the use_id_token_parser_v2 option is enabled.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
Stored XSS persists in error transients. CVE-2026-96765 carries a CVSS score of 7.2. Insufficient input sanitization and output escaping on the id_token parameter let unauthenticated attackers inject arbitrary scripts. The payload is stored in the wpo365_errors transient for up to three days after a crafted request containing malicious HTML in the base64url-decoded unique_name or iss claim. An administrator who later visits the WPO365 wizard page triggers execution.
The payload is stored in the wpo365_errors transient for up to three days after a crafted request containing malicious HTML in the base64url-decoded unique_name or iss claim.
Fixes released in version 45.0. The plugin changelog and code changesets confirm that both issues were addressed in the 45.0 release. Trac references show updates to Id_Token_Service.php, Id_Token_Service_Deprecated.php, Nonce_Service.php, Script_Helpers.php, Log_Service.php, Request_Service.php, and Router_Service.php.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Wordfence rates both issues high severity. The National Vulnerability Database lists the same CVSS vectors supplied by Wordfence. Site owners running the affected integration are advised to update immediately to close the reported attack paths.
Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
securitywordpressvulnerability
More fromNVD
  • System Informer before 4.0.26241.138 exposed to local privilege escalation

    Tech · 15h
  • LobsterAI versions 2026.5.27 to 2026.9.23 contain high-severity directory deletion flaw

    Tech · 16h
  • PHPNuxBill through 2025.3.20 hit by CVE-2026-108108 auth bypass

    Tech · 18h
More inTech
  • Anthropic AI Model Submits False Homicide Tip to Philadelphia Police

    Tech · 6h
  • Modern Warfare 4 DMZ Early Access Opens October 20

    Tech · 17h
  • GlobalFoundries signs $2B TSMC deal for US silicon interposers

    Tech · 1d
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Tech →
  • Tech· 

    System Informer before 4.0.26241.138 exposed to local privilege escalation

    Winsiderss System Informer versions through 4.0.26241.138 contain an incorrect authorization flaw that lets local attackers execute code as SYSTEM from any signed process. Vulncheck rates the issue 7.8 and 8.5.

  • Tech· 

    LobsterAI versions 2026.5.27 to 2026.9.23 contain high-severity directory deletion flaw

    Netease-youdao LobsterAI versions 2026.5.27 through 2026.9.23 contain CVE-2026-108156, a high-severity flaw that enables arbitrary directory deletion via a crafted skill's _meta.json file. The vulnerability carries a CVSS score of 7.1 and requires only that a user install the malicious skill.

  • Tech· 

    PHPNuxBill through 2025.3.20 hit by CVE-2026-108108 auth bypass

    PHPNuxBill through 2025.3.20 is affected by CVE-2026-108108, a CVSS 7.1 authentication bypass in RADIUS CHAP verification. Attackers with a valid username can gain network access and consume customer plans using any password.

  • Tech· 

    IBM Security Verify Access: 4 more vulnerabilities disclosed

    IBM has disclosed four more flaws in Security Verify Access and Verify Identity Access, including a code execution bug it rates critical at 9.1 (NVD: 8.8). Versions 10.0 to 10.0.9.2 and 11.0 to 11.0.3 are affected. IBM says to upgrade to 10.0.9.3 or 11.0.3.1.

  • Tech· 

    Microsoft discloses CVE-2026-83947 in Azure Event Grid

    Microsoft has disclosed CVE-2026-83947, a CVSS 7.7 HIGH spoofing vulnerability in Azure Event Grid caused by missing authorization. Microsoft says it has already fully mitigated the cloud-service flaw and customers have nothing to do.