A vulnerability categorized as problematic has been discovered in WPO365 Login Plugin up to 43.2 on WordPress. The impacted element is the function Ajax_Service::verify_ajax_request/Ajax_Service::update_settings of the component Nonce Verification. Such manipulation of the argument Settings leads to cross-site request forgery.

This vulnerability is documented as CVE-2026-15212. The attack can be executed remotely. There is not any exploit available.