CVE-2020-26511: WPO365 WordPress + Azure Ad / Microsoft Office 365
High severity, CVSS 7.5. EPSS: 2.1% chance of exploitation in the next 30 days.
The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This leads to authentication bypass.
Affected products
- WPO365 WordPress + Azure Ad / Microsoft Office 365: before 11.7 (fixed in 11.7)
Published 2020-10-02. Last modified 2026-06-17.