SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-15212

HIGH · CVSS 8.8 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery, allowing unauthenticated attackers to overwrite arbitrary plugin options due to improper nonce verification. This vulnerability can lead to critical impacts, including the ability to escalate privileges by setting new user roles or enabling sensitive features like the SCIM REST endpoint. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-15212
Severity
HIGH
CVSS
8.8
EPSS
0.16%
WordPress

Original NVD Description

The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_request() helper gating its wp_verify_nonce() call behind the boolean option 'enable_nonce_check', which is absent from the default 'wpo365_options' array and therefore evaluates to false via get_global_boolean_var(); as a result, the wp_ajax_wpo365_update_settings handler (Ajax_Service::update_settings) accepts POSTs from cross-origin pages and forwards the attacker-supplied 'settings' payload (base64/JSON) to Options_Service::update_options(), which merges every key/value into wpo365_options without a key allowlist. This makes it possible for unauthenticated attackers to overwrite arbitrary plugin options — including enabling the SCIM REST endpoint (enable_scim), planting an attacker-known scim_secret_token, and setting new_usr_default_role to 'administrator' — via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.