A critical authentication bypass vulnerability, CVE-2026-2628, has been identified in the All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login WordPress plugin (also known as Login with Azure). According to the NVD entry, all plugin versions up to and including 2.2.5 are vulnerable. An unauthenticated attacker can bypass authentication and log in as arbitrary users, including administrators. The issue is rated CRITICAL (CVSS 3.1 base score 9.8) and can lead to full site takeover, data exposure, and further lateral movement within an affected environment if exploited.
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.
References:

