All verified exploits

CVE-2026-2628 SSO Plugin Authentication Bypass

Deterministic critical WordPress Added cve-verified-cve-2026-2628

Detects the All-in-One Microsoft 365 & Entra ID SSO Login plugin at version 2.2.5 or earlier, where JWT tokens from the browser are accepted without cryptographic signature verification. An unauthenticated attacker can forge a token with any user's email and log in as administrator.

Related WordPress exploits

Is your app exploitable through CVE-2026-2628?

Scan your domain free