CVE-2026-104759 | WPO365 Plugin up to 44.1 on WordPress Deprecated Parser process_openidconnect_token id_token authentication replay
A vulnerability identified as critical has been detected in WPO365 Plugin up to 44.1 on WordPress. The impacted element is the function Id_Token_Service_Deprecated::process_openidconnect_token of the component Deprecated Parser. The manipulation of the argument id_token leads to authentication bypass by capture-replay.
This vulnerability is traded as CVE-2026-104759. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More