Wpo365 develops integration products that bridge WordPress and Microsoft 365 ecosystems, including plugins for Azure AD authentication and mail functionality, with observed vulnerabilities clustering around web-application input handling and authentication bypass mechanisms. The recurring weakness classes—cross-site scripting, improper authentication, and open-redirect flaws—reflect the authentication and identity-brokering role these products occupy between on-premises content systems and cloud identity providers. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpo365 over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-26511HIGH The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This leads to authentication bypass. | Oct 2, 2020 | 7.5 | 24 | NO | NO |
CVE-2021-43409MEDIUM The “WPO365 | LOGIN” WordPress plugin (up to and including version 15.3) by wpo365.com is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored | Nov 19, 2021 | 6.1 | 22 | NO | NO |
CVE-2025-1488MEDIUM The WPO365 | MICROSOFT 365 GRAPH MAILER plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 3.2. This is due to insufficient validation on the | Feb 24, 2025 | 6.1 | 19 | NO | NO |
CVE-2023-32119MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPO365 | Mail Integration for Office 365 / Outlook plugin <= 1.9.0 versions. | Aug 23, 2023 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpo365.
Media articles that mention a CVE ID that affects a product developed by Wpo365 — matched by CVE ID, not by vendor name.