YesWeHack ⠵[verified]@yeswehackPoC
The post announces a critical auth bypass in the WordPress Entra ID/Azure AD SSO plugin (CVE‑2026‑2628) and points readers to a PoC, root‑cause analysis, patch and mitigation details.
Emerson Yougbaré[verified]@emzrsxnActive Exploitation
CVE-2026-1492 is an active, critical flaw in a widely-used WordPress plugin that allows anonymous users to gain admin privileges via a modified sign‑up request; patches are available in recent releases.
Quttera - eCommerce Security[verified]@MNovofastovskyDisclosure
The text announces a critical authentication bypass flaw in a WordPress plugin, explains the risk and recommends updating the plugin and monitoring for compromise.
The Hacker Wire@TheHackerWireDisclosure
The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass in versions up to 2.2.5, with CVE-2026-2628 identified as critical.
UNDERCODE TESTING@UndercodeUpdateDisclosure
The tweet announces CVE‑2026‑2628, describing a critical flaw in the Azure AD SSO plugin that could allow full takeover of WordPress sites, and provides a link to additional details.
Infoflowcloud@infoflowcloudDisclosure
The post announces CVE-2026-2628, an authentication bypass in the All‑in‑One Microsoft 365 & Entra ID/Azure AD SSO Login plugin for WordPress, with no PoC, exploit, or patch details provided.
CVE@CVEnewDisclosure
CVE-2026-2628 exposes an authentication bypass in the All‑in‑One Microsoft 365 & Entra ID / Azure AD SSO Login WordPress plugin (v2.2.5 and earlier). No PoC, exploit, or patch details are provided.
CVEFind.com@CveFindComDisclosure
A critical authentication bypass vulnerability (CVE-2026-2628) exists in the Microsoft 365 & Entra ID/Azure AD SSO Login plugin for WordPress up to v2.2.5, enabling unauthenticated attackers to log in as other users.