CVE-2026-2628Disclosure

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.2.5. This makes it possible for unauthenticated attackers to bypass authentication and log in as other users, including administrators.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • Peaked 4d ago at 4 mentions (2026-03-03); latest day: 1
  • 8 total mentions across 5 days

Deep dive

Activity timeline8 mentions / 5d
01234Mentions · 2026-03-03: 4Mentions · 2026-03-08: 1Mentions · 2026-03-21: 1Mentions · 2026-04-10: 1Mentions · 2026-04-11: 1PoC Mentioned / Linked · 2026-04-10: 1PoC Mentioned / Linked · 2026-04-11: 1Active Exploitation · 2026-03-08: 1Patch / Workaround · 2026-03-08: 1Patch / Workaround · 2026-03-21: 1Patch / Workaround · 2026-04-10: 1Technical Details · 2026-03-03: 4Technical Details · 2026-03-08: 1Technical Details · 2026-03-21: 1Technical Details · 2026-04-10: 1Technical Details · 2026-04-11: 103-0303-0803-2104-1004-11
Signal classification3 categories
Disclosure
675.0%
Active Exploitation
112.5%
PoC
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-034
Disclosure4
2026-03-081
Active Exploitation1
2026-03-211
Disclosure1
2026-04-101
PoC1
2026-04-111
Disclosure1
Full discourse8 posts
  • YesWeHack ⠵@yeswehack
    PoC

    🚨Critical auth bypass in the WordPress Entra ID/Azure AD SSO plugin – attackers could potentially take over admin accounts and fully compromise sites. ⚠️ Root cause, patch analysis, PoC, threat landscape and mitigation steps for CVE-2026-2628 👇 https://www.yeswehack.com/news/auth-bypass-wordpress-azure-plugin?utm_source=twitter&utm_medium=social&utm_campaign=wordpress-azure-plugin

    Post summary

    The post announces a critical auth bypass in the WordPress Entra ID/Azure AD SSO plugin (CVE‑2026‑2628) and points readers to a PoC, root‑cause analysis, patch and mitigation details.

    17053242.7K
    42.1K followersView on X
  • Emerson Yougbaré@emzrsxn
    Active Exploitation

    Un visiteur anonyme peut devenir administrateur de votre site WordPress. Aucun mot de passe à deviner, aucune faille technique complexe à exploiter. Juste une requête d'inscription légèrement modifiée. C'est ce que permet CVE-2026-1492, une vulnérabilité critique découverte dans le plugin User Registration & Membership, installé sur plus de 60 000 sites. Le problème est simple dans son principe : lors de la création d'un compte, le plugin ne vérifie pas correctement les paramètres envoyés par l'utilisateur. En manipulant cette requête, un attaquant peut s'attribuer directement un rôle administrateur sur le site cible. Sans interaction de l'administrateur légitime, sans alerte, sans trace visible. Une fois accès obtenu, les options sont larges : modifier ou supprimer le contenu publié, installer des extensions malveillantes, créer des portes dérobées, extraire la base de données des utilisateurs et de leurs informations de paiement, ou encore évincer les administrateurs existants. Les chercheurs de Wordfence ont déjà bloqué près de 300 tentatives d'exploitation en 48 heures. La faille est donc activement ciblée. Elle affecte toutes les versions du plugin jusqu'à la 5.1.2. Le correctif est disponible dans la version 5.1.3, la 5.1.4 étant la plus récente. La version payante Pro ne semble pas concernée. Une seconde vulnérabilité a été corrigée dans le même temps, cette fois dans le plugin All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login (CVE-2026-2628). Elle permet à un attaquant non authentifié de contourner la procédure de connexion et d'accéder au site en se faisant passer pour n'importe quel utilisateur, y compris les administrateurs. Ce plugin est déployé sur plus de 600 sites. Pour les PME qui s'appuient sur WordPress pour leur site vitrine, leur boutique en ligne ou leur portail client : vérifiez vos plugins actifs, mettez à jour immédiatement vers les versions corrigées, et profitez-en pour passer en revue l'ensemble des extensions installées. Un plugin inutilisé et non mis à jour est une surface d'attaque qui coûte rien à éliminer. Source : Wordfence - lien en commentaire. #Cybersécurité #WordPress #Vulnérabilité #GestionDesRisques #PME #GRC #VeilleInformationnelle

    Post summary

    CVE-2026-1492 is an active, critical flaw in a widely-used WordPress plugin that allows anonymous users to gain admin privileges via a modified sign‑up request; patches are available in recent releases.

    2000056
    1.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-2628 - Critical The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.2.5. This makes it possible... https://www.thehackerwire.com/vulnerability/CVE-2026-2628/ https://t.co/OhpnVPHRyT

    Post summary

    The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass in versions up to 2.2.5, with CVE-2026-2628 identified as critical.

    0000159
    121 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Disclosure

    🚨 #CVE-2026-2628: Critical #Azure AD SSO Plugin Flaw Exposes WordPress Sites to Full Takeover https://undercodetesting.com/cve-2026-2628-critical-azure-ad-sso-plugin-flaw-exposes-wordpress-sites-to-full-takeover/ Educational Purposes!

    Post summary

    The tweet announces CVE‑2026‑2628, describing a critical flaw in the Azure AD SSO plugin that could allow full takeover of WordPress sites, and provides a link to additional details.

    0000060
    464 followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Disclosure

    Critical #WordPress Security Alert: CVE-2026-2628 A critical authentication bypass flaw in the WordPress plugin All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login affects all versions through 2.2.5. It could let unauthenticated attackers log in as other users — even administrators. ⚠️ Why it matters: A bug in an SSO plugin can turn identity trust into a direct compromise path. If exploited, attackers may gain full admin access and take over the site without valid credentials. 🛠 Mitigation: Update the plugin immediately once a fixed version is available, review admin accounts and login activity for anomalies, and scan the site for signs of post-compromise persistence. #WordPressSecurity #CVE #CyberSecurity #SSO #AuthenticationBypass #WebsiteSecurity #ThreatDetection

    Post summary

    The text announces a critical authentication bypass flaw in a WordPress plugin, explains the risk and recommends updating the plugin and monitoring for compromise.

    0000055
    37 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-2628 The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.2.5. Th… https://www.cve.org/CVERecord?id=CVE-2026-2628 ----- Traducción: CVE-2026-2628 El … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-2628, an authentication bypass in the All‑in‑One Microsoft 365 & Entra ID/Azure AD SSO Login plugin for WordPress, with no PoC, exploit, or patch details provided.

    0000047
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2628 The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.2.5. Th… https://www.cve.org/CVERecord?id=CVE-2026-2628

    Post summary

    CVE-2026-2628 exposes an authentication bypass in the All‑in‑One Microsoft 365 & Entra ID / Azure AD SSO Login WordPress plugin (v2.2.5 and earlier). No PoC, exploit, or patch details are provided.

    00000344
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-2628: CRITICAL] Vulnerability in Microsoft 365 & Entra ID/Azure AD SSO Login plugin for WordPress (up to v2.2.5) allows unauthenticated attackers to bypass authentication and log in as other users. #...#cve,CVE-2026-2628,#cybersecurity https://cvefind.com/CVE-2026-2628

    Post summary

    A critical authentication bypass vulnerability (CVE-2026-2628) exists in the Microsoft 365 & Entra ID/Azure AD SSO Login plugin for WordPress up to v2.2.5, enabling unauthenticated attackers to log in as other users.

    0000086
    593 followersView on X

Explore more