CVE-2026-15212

WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 43.2 - Cross-Site Request Forgery to Privilege Escalation via Plugin Settings Update

The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_request() helper gating its wp_verify_nonce() call behind the boolean option 'enable_nonce_check', which is absent from the default 'wpo365_options' array and therefore evaluates to false via get_global_boolean_var(); as a result, the wp_ajax_wpo365_update_settings handler (Ajax_Service::update_settings) accepts POSTs from cross-origin pages and forwards the attacker-supplied 'settings' payload (base64/JSON) to Options_Service::update_options(), which merges every key/value into wpo365_options without a key allowlist. This makes it possible for unauthenticated attackers to overwrite arbitrary plugin options — including enabling the SCIM REST endpoint (enable_scim), planting an attacker-known scim_secret_token, and setting new_usr_default_role to 'administrator' — via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.


We have discovered 1,635 live websites that are affected by CVE-2026-15212.

Run a Free Instant Scan




Affected Software

Product  Wpo365 Login
Category Wordpress Plugins
Vulnerable Domains1,635 live websites (100% of Wpo365 Login install base)
Vulnerable Versions
  • from 0 through 43.2
Vulnerable Versions Count74 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-352 Cross-Site Request Forgery (CSRF)



Details

  • Published - Jul 23, 2026
  • Updated - Jul 24, 2026

Credits

  • Osvaldo Noe Gonzalez Del Rio (Os) (finder)

Website Distribution by Country

Number of websites using CVE-2026-15212
United States672 websites



Germany154 websites
Canada95 websites
GB69 websites
France62 websites
Australia56 websites
Italy54 websites
Netherlands45 websites
Poland38 websites
Sweden33 websites

Website Distribution by TLD

Number of websites using CVE-2026-15212
.com511 websites
.org168 websites
.de120 websites
.ca85 websites
.edu66 websites
.nl39 websites
.com.au38 websites
.it32 websites
.se30 websites
.pl27 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-15212

Top websites that are affected by CVE-2026-15212. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.***.br Brazil**,***
***********.nl United States**,***
*******.com United States**,***
***.fi Finland**,***
**************.com United States**,***
******.org United States**,***
*********.com Netherlands**,***
***.org United States**,***
*********.com France**,***
***.ee Estonia**,***
See full domain list

FAQ

CVE-2026-15212 is Cross-Site Request Forgery (CSRF) in Wpo365 Login
A total of 1,635 websites have been identified as vulnerable to CVE-2026-15212, based on global website indexing conducted by WebTechSurvey.
The Wpo365 Login is affected by the CVE-2026-15212 vulnerability.
Wpo365 Login versions up to and including 43.2 are vulnerable to CVE-2026-15212.