WordPress Plugin Vulnerabilities

All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login < 2.2.6 - Authentication Bypass

Description

The plugin is vulnerable to authentication bypass . This makes it possible for unauthenticated attackers to bypass authentication and log in as other users, including administrators.

Affects Plugins

Fixed in 2.2.6

References

Classification

Miscellaneous

Original Researcher
Nabil Irawan
Verified
No

Timeline

Publicly Published
2026-03-02 (about 6 months ago)
Added
2026-03-02 (about 6 months ago)
Last Updated
2026-09-23 (about 6 days ago)

Other