HIGH

CVE-2026-15212

CVSS v3

8.8

HIGH

EPSS Score

0.2%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_request() helper gating its wp_verify_nonce() call behind the boolean option 'enable_nonce_check', which is absent from the default 'wpo365_options' array and therefore evaluates to false via get_global_boolean_var(); as a result, the wp_ajax_wpo365_update_settings handler (Ajax_Service::update_settings) accepts POSTs from cross-

Technical details

CVSS v3 Vector
3.1
Published
7/23/2026
Last Modified
7/23/2026

Frequently asked questions

What is CVE-2026-15212?

The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_request() helper gating its wp_verify_nonce() call behind the boolean option 'enable_nonce_check', which is absent from the default 'wpo365_options' array and therefore evaluates to false via get_global_boolean_var(); as a result, the wp_ajax_wpo365_update_settings handler (Ajax_Service::update_settings) accepts POSTs from cross-

Is CVE-2026-15212 actively exploited?

Active exploitation of CVE-2026-15212 has not been confirmed. The EPSS score is 0.2%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-15212?

CVE-2026-15212 has a CVSS v3 base score of 8.8 (HIGH severity), with vector string 3.1.

Is CVE-2026-15212 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.