Latest changes
5th September 2026 / v44.1
- FIX Microsoft’s infrastructure is currently incompatible with OpenSSL 3.5 and higher’s new default settings (as shipped with e.g. Debian 13), which could make sign-in or Microsoft Graph requests unexpectedly fail with a “Not Found” error on affected web hosts (e.g. IONOS / Fasthosts) – the plugin now automatically detects this and works around it. [LOGIN, MAILER] Read more
1st September 2026 / v44.0
- Support for WordPress 7.1. [ALL]
- FEATURE Use Copilot Rewrite – a block-editor sidebar tool – to rewrite selected content blocks (paragraphs, headings, lists, quotes, code, and more) with AI assistance, including support for personal and organization-wide rewrite instructions. [ESSENTIALS, PROFESSIONAL, INTEGRATE (LOGIN+, SYNC, INTRANET)] Read more
- FEATURE Copilot Chat is a new app that lets visitors have an AI-powered conversation grounded in your organization’s Microsoft 365 / SharePoint content, embeddable anywhere on your WordPress site – with conversation export, retry-on-failure, source attributions, and custom styling support. [APPS, INTEGRATE (INTRANET)] Read more
- FEATURE Enable a fully customizable WordPress Login Page at https://{your website}/wpo/Login and optionally hide the classic WordPress page “/wp-login.php”, with an option to hide the username / password form, custom branding, layout (single or split-column), colors, logo, custom title / description text, and translatable labels. [ESSENTIALS, PROFESSIONAL, INTEGRATE (LOGIN+, SYNC, INTRANET)] Read more
- FEATURE Added a matching custom “Logged Out” page (‘/wpo/loggedout’) that can be used as the default landing page after sign-out or an SSO sign-in error, without needing a separately configured error page. [ESSENTIALS, PROFESSIONAL, INTEGRATE (LOGIN+, SYNC, INTRANET)]
- IMPROVEMENT A fully redesigned, more compact calendar list layout with a day-badge, and a combined start/end time column. Events that span multiple days or last all day are now displayed more clearly, showing correct start / end dates and an “All day event” label instead of confusing time ranges. [LOGIN, APPS, INTEGRATE (INTRANET)] Updated screenshots
- IMPROVEMENT The plugin will now – on a daily base – automatically refresh the Microsoft Graph mail connection’s access and refresh token, so outgoing mail no longer risks failing due to a long-expired token after periods of low activity. [LOGIN, MAILER] Consult the update tutorial
- IMPROVEMENT Added automatic detection and suppression of duplicate outgoing emails sent within a short time window. [LOGIN, MAILER] Read more
- IMPROVEMENT The existing “obfuscate Entra ID options” switch – that will delete sensitive Entra ID settings from the database once they’re defined in ‘wp-config.php’ when toggled on – is now capable of automatically restoring those settings if switched off again. [ANY PREMIUM] Read more
- IMPROVEMENT Added an optimized mobile layout option (portrait or landscape) for embedded Power BI reports on narrow screens. [APPS, INTEGRATE (INTRANET)]
- IMPROVEMENT The “Sign in with Microsoft” button – when multiple identity providers are configured – now highlights the identity-provider dropdown in red if you try to sign in without picking one, instead of just leaving the button disabled with no explanation. [LOGIN]
- IMPROVEMENT The “block direct Media Folder access” feature now (again) support a “Secure Download Mode” for Litespeed servers (requires additional server-configuration – consult online documentation). [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMER (LOGIN+, SYNC, INTRANET)]
- IMPROVEMENT Added “Default LD assignment scope” as an additional option to configure default LearnDash course and group assignments, so you can control whether those assignments should be applied to new users only, instead of always being applied to all users. [ROLES + ACCESS, PROFESSIONAL, INTEGRATE, CUSTOMERS (SYNC, INTRANET)] Read more
- IMPROVEMENT The plugin’s built-in “Send WordPress emails using Microsoft Graph” feature nows honor a “Retry-After” header – when Microsoft Graph throttles a request – with a short automatic retry, instead of failing immediately. [LOGIN, MAILER]
- IMPROVEMENT If you have configured multiple Identity Providers, you can now configure the “Allow users from other tenants” setting individually for each identity provider in wp-config.php. [LOGIN]
- FIX Tested for compatibility with multilingual plugins that add language-specific URL paths, such as “/en” and “/nl”. [LOGIN]
- FIX The start / end date and time of Calendar app events are now correctly translated to the user’s timezone. [LOGIN, APPS, INTEGRATE (INTRANET)]
- FIX The “Access Denied” message shown to users blocked for not belonging to a required group has been corrected to a more accurate, specific message. [ROLES + ACCESS, PROFESSIONAL, INTEGRATE, CUSTOMERS (SYNC, INTRANET)]
- FIX The wizard no longer shows a misleading “invalid secret” warning for a masked secret field when Entra ID options have been obfuscated. [ANY PREMIUM]
- FIX Identified a bug where selecting a specific identity provider from a multi-tenant sign-in dropdown when “Use client-side redirect” has been selected, would drop the selected Identity Provider, incorrectly falling back to the default identity provider. [LOGIN]
- FIX On a WordPress Multisite installation, the “block direct Media Folder access” feature would generate a download-authorization cookie for one network site and replay it when connected to another network site. Now the service includes a host check, when validating the cookie. [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMER (LOGIN+, SYNC, INTRANET)]
- FIX A new installation of the WPO365 | LOGIN plugin will no longer produce an initial “List of pages freed from authentication” with absolute URLs but with site relative paths instead – to prevent a WPO365 Health Message from showing up. [LOGIN]
- FIX The SSO bypass cookie (set by the plugin when SSO for the login page is enabled and the correct secret has been added to the login page URL) was being cleared immediately after being set under certain circumstances, preventing the bypass from working beyond the first page load. [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMERS (LOGIN+, SYNC, INTRANET)]
- FIX If you have configured multiple Identity Providers, the plugin can now refresh access tokens for users who signed in using a non-default Identity Provider. [LOGIN]
- This release updates the version numbers of all premium plugins to 44.0 to align with the core plugin WPO365 | LOGIN.
23rd July 2026 / v43.4
- FIX Fixed an issue on WordPress Multisite installations where content embedded from another site could fail to render when WPO365 Audiences was enabled. [ROLES + ACCESS, PROFESSIONAL, CUSTOMERS, INTEGRATE (SYNC, INTRANET)]
- FIX Fixed an issue where a double forward slash inside a query string value (e.g. “https://” within a redirect_to parameter) could be incorrectly collapsed to a single slash while the plugin sanitized the current request URL, which could prevent users from signing in successfully. [LOGIN, MAILER]
17th July 2026 / v43.3
- SECURITY FIX Strengthened verification of certain AJAX requests to help prevent unauthorized changes to plugin settings. [ALL]
6th July 2026 / v43.2
- FIX Fixed an issue that prevented externally triggered WPO365 User Synchronization jobs from starting via the public “?wpo365_sync_run” endpoint. [INTEGRATE, CUSTOMERS (SYNC, INTRANET)]
- FIX Removed support for the LiteSpeed-specific “Secure Download Mode” that relied on the X-LiteSpeed-Location header due to technical issues. [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMERS (LOGIN+, SYNC, INTRANET)]
- FIX Added no-cache headers to responses generated by the custom endpoint that initiates single sign-on, helping prevent client-side caching issues that could result in “nonce not found” exceptions. [LOGIN]
26th June 2026 / v43.1
- FIX Fixed an issue that could prevent anonymous AJAX requests (admin-ajax.php) from working correctly on WordPress sites that configured WPO365 Intranet Mode. [LOGIN]
- FIX Administrators are now allowed to exclude site-relative paths that start with “/wp-admin”. [LOGIN]
25th June 2026 / v43.0
- BREAKING CHANGE To address multiple vulnerabilities that could allow attackers to bypass WPO365 Intranet Mode, entries in the “Pages freed from authentication” list are now interpreted as server-relative paths. All entries must start with a forward slash (/) and are matched against the beginning of the requested URI path. Consult this article for details. [LOGIN, MAILER]
- This release updates the version numbers of all premium plugins to 43.0 to align with the core plugin WPO365 | LOGIN. No functional changes were made to the premium plugins.
23rd June 2026 / v42.11
- CHANGE The plugin will no longer redirect AJAX and REST request to Microsoft but instead return a 401 Unauthorized message and terminate the connection. [LOGIN]
- IMPROVEMENT A new hand-off mode can now be configured for protected Media Library downloads, helping improve performance and the delivery of large files. See updated documentation for details. [ESSENTIALS, PROFESSIONAL, CUSTOMERS, INTEGRATE (LOGIN+, SYNC, INTRANET)]
- FIX Fixed Teams silent authentication, which could fail when an internal redirect to the custom SSO endpoint interrupted the authentication response. [LOGIN]
- FIX The SCIM manager attribute is now returned as a complex object, in line with Entra ID expectations, to prevent provisioning errors. [SCIM, INTEGRATE, (INTRANET)]
- FIX Manager IDs received from Entra ID are now stored as user meta (with key “wpo365_manager_id”). When enabled, the user profile displays a link to view the corresponding WordPress manager. [SCIM, INTEGRATE (SYCN, INTRANET)]
- FIX the SCIM userName property’s value is now sourced from Entra ID’s userPrincipalName (by default always stored as user meta with key “userPrincipalName”), replacing the WordPress username – used previously – to prevent mismatches and provisioning errors. [SCIM, INTEGRATE (INTRANET)]
- FIX Users deactivated in Entra ID and synchronized as inactive in WordPress are now correctly reactivated in WordPress when re-enabled in Entra ID. [SCIM, INTEGRATE (INTRANET)]
- FIX WPO365 Insights will now correctly log all updated user attributes when more than one is patched by the integration with Microsoft Entra ID’s Application Provisioning Service. [SCIM, INTEGRATE (INTRANET)]
- FIX A reactivation button is now correctly displayed on the WordPress “Users” page when a user is deactivated and Entra ID Application Provisioning integration is enabled. [SCIM, INTEGRATE (INTRANET)]
- FIX The identity provider dropdown on the login page now consistently displays the default placeholder text when multiple providers are configured. [LOGIN]
- FIX Fixed broken and outdated links in the plugin wizard. [LOGIN, MAILER]
5th June 2026 / v42.10
- FIX Updated phpseclib to version 3.0.52 (was 3.0.43), which patches CVE-2026-44167. [LOGIN, MAILER]
- FIX Resolved an issue where WordPress 7 styles forced showing an unwanted border on the Toast element (for displaying embed-app errors) [LOGIN, APPS, INTEGRATE (INTRANET)]
2nd June 2026 / v42.9
- FIX Fixed an issue where incorrect URL encoding caused query string parameters to be lost when redirecting users to their originally requested page. [LOGIN]
- FIX The plugin will now load modern JavaScript modules correctly on a subdomain-based WordPress Multisite installation, to avoid CORS related issues. [LOGIN]
2nd June 2026 / v42.8
- FIX Improved the interim-login experience when a WordPress session expires. The plugin now detects this scenario earlier and ensures the “Session expired” prompt is shown. [LOGIN]
1st June 2026 / v42.7
- FIX Resolved an issue that prevented the plugin from forcing Single Sign-on for the login page when a custom authentication scenario WPO_AUTH_SCENARIO has been defined (in wp-config.php). [LOGIN]
1st June 2026 / v42.6
- FIX Resolved an issue that prevented the plugin from redirecting the user back to the URL they intended to navigate to, before WPO365 initialized SSO and sent the user to Microsoft to authenticate. [LOGIN]
- FIX Resolved an issue preventing the plugin from using the selected Identity Provider (when multiple Identity Providers have been configured) when “Use client-side redirect” was enabled.
28th May 2026 / v42.5
- FIX Resolved an issue that prevented Single Sign-On from starting when a custom authentication scenario WPO_AUTH_SCENARIO was defined (in wp-config.php) in combination with using client-side redirection to Microsoft (see option “Use client-side redirect on the plugin’s “Login / logout” configuration page). [LOGIN]
26th May 2026 / v42.2
- FIX Resolved an issue that could prevent Single Sign-On from starting when the request URL was altered by plugins, reverse proxies, or subdirectory setups. [LOGIN]
26th May 2026 / v42.3
- FIX Resolved an issue that prevented Single Sign-On from starting when a custom authentication scenario WPO_AUTH_SCENARIO was defined (in wp-config.php). [LOGIN]
22nd May 2026 / v42.2
- FIX To maintain compatibility with legacy premium Power BI embed-app configurations, the plugin now automatically converts specific string values into arrays when processing manually edited Token Request JSON. [LOGIN]
- FIX The body of the email sent when an (OpenID Connect) Application (Client) Secret is about to expire now includes the blog’s name. [LOGIN]
21st May 2026 / v42.1
- IMPROVEMENT Redirection to Microsoft for SSO now consistently routes through the plugin’s custom endpoint /wpo/sso/start. This allows administrators to exclude a single endpoint from caching, ensuring reliable nonce verification and preventing cache-related errors such as Your login has been tampered with. Read this article to get a better understanding. [LOGIN, MAILER, ESSENTIALS, PROFESSIONAL, CUSTOMERS, INTEGRATE (LOGIN+, SYNC, INTRANET)]
- FIX Dynamic tokens such as “wp_user_email” in a custom Power BI token request JSON are once again properly resolved to their corresponding values. [APPS, INTEGRATE (INTRANET)]
- FIX Translation for the Your login has been tampered with error is now correctly resolved. [LOGIN, MAILER]
19th May 2026 / v42.0
- CHANGE To improve and streamline the Microsoft Single Sign-On flow, authentication is now consistently initiated via the /wpo/sso/start endpoint (or ?wpo_sso_start=1 without permalinks), and all login buttons have been updated accordingly. See the updated online documentation for details. [LOGIN, MS GRAPH MAILER]
- IMPROVEMENT You can now send emails from alias addresses when using Microsoft Graph, enabling more tailored and professional communication. Consult the online documentation for details. [MAIL, PROFESSIONAL, INTEGRATE, CUSTOMERS (SYNC, INTRANET)]
- IMPROVEMENT New you can configure the SharePoint Library (premium) embed-app to hide folders and enforce file downloads (instead of opening files in Microsoft 365). [APPS, INTEGRATE (INTRANET)]
- IMPROVEMENT Completely refactored the WPO365 User Synchronization feature for improved reliability e.g. to eliminate caching issues with expired next-links and enhance logging for better diagnostics. [INTEGRATE (SYNC, INTRANET)]
- IMPROVEMENT Users of the new automated embed-app configurator can now duplicate apps – allowing them to effectively create an embed-app template. [LOGIN, APPS, INTEGRATE (INTRANET)]
- FIX Nonce handling has been enhanced to prevent caching issues and ensure more secure authentication requests. [LOGIN, MS GRAPH MAILER]
- FIX Enhanced Microsoft Teams experience by updating to the latest Microsoft Teams JavaScript SDK. Also refactored existing support for embedded WordPress running in an iframe. [LOGIN]
- FIX Media Folder protection now supports query string variables for greater flexibility. Administrators using Apache should reinitialize the feature to apply the required .htaccess updates. [ESSENTIALS, PROFESSIONAL, CUSTOMERS, INTEGRATE (SYNC, INTRANET)]
- FIX Resolved a race condition in the automated embed-app configurator that could overwrite existing configuration and lead to permission-related issues. [LOGIN, APPS, INTEGRATE (INTRANET)]
- FIX Users of the new automated embed-app configurator are now asked to choose between embedding for their organization or for customers to ensure the correct permissions are applied – when applicable. [APPS, INTEGRATE (INTRANET)]
- FIX Users of the new automated embed-app configurator for Power BI are now able to configure XmlaPermissions (for Paginated Reports). [APPS, INTEGRATE (INTRANET)]
- FIX Resolved several issues affecting configurations with multiple Identity Providers. [ESSENTIALS, PROFESSIONAL, CUSTOMERS, INTEGRATE (LOGIN+, SYNC, INTRANET)]
- Support for WordPress 7.0.
13th April 2026 / v41.3
- FIX The Mail Log Viewer now reliably displays attachment names without crashing. [LOGIN, MAILER]
- FIX Corrected an issue that could cause a crash while generating client secret expiration warning emails. [LOGIN, MAILER]
- FIX Resolved a “Failed to execute ‘querySelector’ on ‘Document'” error in the wizard app triggered by invalid auto-generated element IDs. [LOGIN, MAILER]
10th April 2026 / v41.2
- FIX Prevented duplicate or incorrect type attributes on script tags, which could cause “Cannot use import statement outside a module” errors. [LOGIN]
- FIX Resolved a critical error that could occur when obtaining an access token for an embed-app due to an undefined method call. [LOGIN]
- FIX Automatically disables SSO when the mail function is invoked in the context of the WPO365 | MICROSOFT GRAPH MAILER plugin (preventing the plugin from logging SSO-unconfigured warnings). [MAILER].
2nd April 2026 / v41.1
- FIX Prevented duplicate or incorrect type attributes on script tags, which could cause “Cannot use import statement outside a module” errors when loading apps to embed Power BI or M*365 services such as SharePoint, Entra ID and Exchange. [LOGIN, MAILER]
30th March 2026 / v41.0
- CHANGE Added a brand‑new M*365 Apps Framework for embedding content from SharePoint Online, Microsoft Entra ID, Exchange Online, and Power BI, with persistent app configuration stored in the database, a preview option, and a guided configuration wizard. [LOGIN, APPS, INTEGRATE (INTRANET)]
- CHANGE Redesigned the menu of the plugin’s Configuration Pages – new with a new vertical navigation. [ALL]
- IMPROVEMENT To align with Microsoft’s current branding, Azure AD has been renamed to Microsoft Entra ID throughout the plugin, and all portal links now open in entra.microsoft.com. [ALL]
- IMPROVEMENT Added major enhancements to the premium SharePoint Library embed: users can now search the library, upload files, and choose from new card templates or a more customizable HTML table view. [APPS, INTEGRATE (INTRANET)]
- IMPROVEMENT Enhanced the Exchange Online Calendar embed-app, including a date picker with event cards, and support for displaying events across a rolling one‑year period. [APPS, INTEGRATE (INTRANET)]
- IMPROVEMENT Refactored the plugin’s “User Registration” configuration page and moved “Roles + Access” to its own configuration page for better clarity and maintainability. [LOGIN]
- FIX Fixed an issue in the stand‑alone WPO365 | MICROSOFT GRAPH MAILER plugin and tested and confirmed compatibility with GCC High tenants. [MAILER]
- FIX The WPO365 | PROFESSIONAL now ships with the required integration source code for itthinx Groups. [PROFESSIONAL]
- FIX Updated the Exchange Online Calendar embed-app so links in event descriptions now open in a new tab. [LOGIN, APPS, INTEGRATE (INTRANET)]
- FIX Dropped the core‑js polyfill dependency as it is no longer required by the plugin. [LOGIN]
20th February 2026 / v40.3
- IMPROVEMENT Protecting the Media Library by restricting access to logged-in users is now also supported for Auth.-Only authentication scenarios. [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMERS (LOGIN+, SYNC INTRANET)]
- IMPROVEMENT When protection of the Media Library is enabled, WPO365 will award a cookie when a user signs in with SSO, further optimizing the performance. [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMERS (LOGIN+, SYNC INTRANET)]
- FIX When a cookie granting access to the Media Library is not found, WordPress will now loaded in an isolated function to prevent conflicts with other variables. [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMERS (LOGIN+, SYNC INTRANET)]
- FIX The exported SAML 2.0 service provider XML configuration file is now “well-formed”. [LOGIN]
- FIX The ROLES + ACCESS (premium) plugin now includes the mapping tool for itthinx Groups. [ROLES + ACCESS]
- FIX The SCIM (premium) plugin now unlocks the “custom field mapping tool” on the plugin’s “User Sync” configuration page. [SCIM]
15th December 2025 / v40.2
- SECURITY FIX An XSS vulnerability has been patched. [ALL]
11th December 2025 / v40.1
- FIX Two free / basic apps for embedding Microsoft 365 services — SharePoint Online Search and Employee Directory — failed to perform their search functionality. [LOGIN]
7th December 2025 / v40.0
- SECURITY FIX A Server Side Request Forgery (SSRF) vulnerability has been patched. [ALL]
- BREAKING CHANGE The long-term deprecated version of WPO365 User Synchronization has now been removed. [INTEGRATE (SYNC, INTRANET)]
- IMPROVEMENT When an administrator enables WPO365’s “shared” WPMU-mode, WPO365 can now be configured to update the user’s WordPress role(s) based on your Entra group-to-WP-role mappings not only for the current site, but also for all subsites where the user is a member. See the online documentation for details. [ROLES + ACCESS, PROFESSIONAL, INTEGRATE, CUSTOMERS (SYNC, INTRANET)]
- IMPROVEMENT This version introduces a number of enhancements when embedding an Outlook / Exchange Online calendar in WordPress:
- The free version now supports clickable items to pop up a dialog with the event’s details.
- Premium versions can now also use a Shared Calendar as their source.
- The event’s HTML content will now be rendered in an iframe.
- Event details will now list the event start and end date, location and a clickable link in case of an online meeting.
- By default will (new) calendars show an extra column for the event’s end date.
- Multi-day events are now easily identifiable by a dedicated icon.
- See the updated feature documentation.
- IMPROVEMENT Confirms support for WordPress 6.9. [ALL]
- IMPROVEMENT When embedding Power BI content in WordPress for customers, WPO365 will now also update dynamic tokens found in an Effective Identity’s customData property. The online documentation has been updated to reflect this. [APPS, INTEGRATE (INTRANET)]
- IMPROVEMENT Direct Access to the Media Library now uses a cookie, to prevent 429 Too Many Requests errors and to reduce the server load. The online documentation has been updated accordingly. [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMERS (LOGIN+, SYNC, INTRANET)]
- FIX When WPO365 User Synchronization is triggered via an external link, WPO365 now waits for WordPress to fully initialize, ensuring that all hooks (filters and actions) are properly attached. [INTEGRATE (SYNC, INTRANET)]
13th November 2025 / v39.0
- FEATURE Now you can block direct access to the Media Library, when the selected Authentication scenario is Intranet. Refer to the implementation guide for instructions and restrictions. [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMERS (LOGIN+, SYNC, INTRANET)]
- Feature Administrators can now add a new WordPress user from Entra ID directly from WordPress’s built-in Add New User page. Checkout the implementation guide. [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMERS (LOGIN+, SYNC, INTRANET)]
- IMPROVEMENT Embed Paginated Reports from Power BI in WordPress. Consult the all new Power BI / WordPress integration tutorial. [M365 APPS, INTEGRATE (INTRANET)]
- IMPROVEMENT When emails are successfully sent during a retry, the corresponding error message is removed, and the error count on the WPO365 | INSIGHTS Dashboard is updated accordingly. [ALL]
- IMPROVEMENT Sending WordPress emails via Microsoft Graph is now supported for GCC High tenants. [ALL]
- FIX SCIM options are now available (again) when the INTRANET premium plugin is detected. [INTRANET]
- FIX The availability of WPO365 configuration pages—and optionally the license management page—at the network admin level in WordPress Multisite has been reviewed and improved. [ALL]
- FIX Usability of the Feature status and toggle on the WPO365 Dashboard page has been reviewed and improved. [ALL]
- FIX The Plugin Self-Test now recognizes if a “groups” claim was received as part of the ID token / SAML response. [ROLES + ACCESS, PROFESSIONAL, INTEGRATE (SYNC, INTRANET)]
2nd September 2025 / v38.0
- FEATURE See what matters, when it happens Track key WPO365 events like logins, sent emails and user creation and updates with WPO365 Insights and get alerted when when a critical WPO365 event occurs. Consult the updated documentation for instructions how to configure WPO365 Alerts. [ALL PREMIUM]
- IMPROVEMENT A new Daily WPO365 Insights widget has been added to the WP Admin Dashboard, informing administrator about key WPO365 events like logins, sent emails and user creation and updates. Refer to the update documentation for further details or how to hide the widget. [ALL]
- IMPROVEMENT Links found in the SharePoint Library will now open the linked document directly when clicked. [ALL]
- IMPROVEMENT Custom user metadata that is collected during user registration is now be available when the plugin creates a new user in Azure AD B2C / Entra Ext. ID. [CUSTOMERS]
- FIX If the “Public hompage” option is enabled, WPO365 will now also allow more complex requests containing query parameters. [ALL PREMIUM]
- FIX The plugin checks whether the request parameter with the key idp_id was added by WPO365, and ignores it if not. [ALL PREMIUM]
- FIX WPO365 will now use a regular WordPress site option (instead of a transient option) to temporarily save the pre-authenticated link to retrieve the next batch of users during user synchronization. [INTEGRATE, CUSTOMERS (SYNC, INTRANET)]
- FIX The plugin will now overwrite user identifiers saved as usermeta such as the Entra Tenant ID, Object ID and UPN whenever a user is updated, to make it easier to migrate from one directory to another e.g. AAD B2C to Entra Ext. ID. [CUSTOMERS]
- FIX Addressed various technical problems to enhance plugin reliability. [ALL]
15th July 2025 / v37.2
- FIX WPO365 will avoid using “wp_print_inline_script_tag” and instead create a “script” tag itself, if the active WordPress theme does not declare support for the ‘html5’ and ‘script’ features. [ALL]
14th July 2025 / v37.1
- IMPROVEMENT The built-in WordPress Mailer for Microsoft Graph now supports RBAC for Exchange Online. As a result, administrators should now explicitely configure the desired authorization scenario, as explained in a new lesson in the tutorial. [LOGIN, MICROSOFT GRAPH MAILER]
- IMPROVEMENT All scripts now are created using either wp_print_script_tag or wp_print_inline_script_tag. As a result, developers can add your own nonce attribute using the wp_script_attributes and wp_inline_script_attributes filters e.g. to enable a Content-Security-Policy (or CSP). [LOGIN, MICROSOFT GRAPH MAILER]
- FIX For premium plugins, WPO365 would check the license status with every admin request, which could slow down your site unnecessarily. [ALL PREMIUM]
- FIX Some features were not included in the Plugin Self-Test for the CUSTOMERS premium plugin. [CUSTOMERS]
17th June 2025 / v37.0
- IMPROVEMENT As of version 37.0, creating new users through the SCIM-based integration with the Microsoft Entra ID Application / User Provisioning service is now available as a free feature. Get started today! [LOGIN]
- IMPROVEMENT Beginning with version 37.0, WPO365 | LOGIN – available at no cost – can now also populate a new WordPress user’s name and email profile attributes, a capability that previously required the PROFILE+ add-on. [LOGIN]
- IMPROVEMENT It is now possible to schedule WPO365 User Synchronization without the need to rely on WP Cron by triggering both the start of a new user-sync job and the processing of each batch using an external task scheduler. See the updated tutorial for details. [INTEGRATE (SYNC, INTRANET)]
- IMPROVEMENT A new filter has been added that allows developers to filter the custom Error Page URL. Consult the updated documentation for details. [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMERS (LOGIN+, SYNC, INTRANET)]
- IMPROVEMENT Administrators experiencing issues with WPO365 User Synchronization or the SCIM-based integration with the Microsoft Entra ID Application / User Provisioning service, can now enable a custom logging function that helps collect more data in a separate server log. [SCIM, INTEGRATE, CUSTOMERS (SYNC, INTRANET)]
- FIX An issue – previously causing a critical error when creating a new WordPress Network Subsite for a new user without a valid email address – has been resolved. [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMERS (LOGIN+, SYNC, INTRANET)]
- FIX A bug has been fixed that prevented WPO365 from detecting whether or not a user should be considered a user that signed in with Microsoft and preventing users from changing their email address or password. [LOGIN]
- FIX A few issues related to saving an (updated) WPO365 configuration (as JSON) on the plugin’s “Import / Export” page have been addressed.
- FIX The sub headers of the wizard now support rtl-direction.
18th April 2025 / v36.2
- FIX Functionality for forcing SSO for the (default / custom) login page has been restored. [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMERS (LOGIN+, SYNC, INTRANET)]
17th April 2025 / v36.1
- IMPROVEMENT Confirms support for WordPress 6.8. [ALL]
- IMPROVEMENT An administrator can define a (list of) referrer(s) that are allowed to send credentials to the login page when SSO is forced for the login page. [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMERS (LOGIN+, SYNC, INTRANET)]
- IMPROVEMENT Configuring a “GCC (High)” tenant using wp-config.php is now supported for both single and multiple IdP scenarios. [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMERS (LOGIN+, SYNC, INTRANET)]
- FIX The function of the “Public Homepage” setting has been restored. [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMERS (LOGIN+, SYNC, INTRANET)]
- FIX Support for the plugin User Switching has been restored when SSO is forced for the login page. [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMERS (LOGIN+, SYNC, INTRANET)]
- FIX When an administrator configures WPO365 for WPMU to allow partial independence for each subsite, WPO365 will now always require users to re-authenticate when navigating between subsites. [ALL]
- FIX When “WPO365 User Synchronization” fails because its next-link has expired, it will now correctly send a “failure” notification. [INTEGRATE (SYNC, INTRANET)]
11th March 2025 / v36.0
- BREAKING CHANGE A previous update that redirected users without privileges for the site they requested to their dashboard URL or primary site in a WordPress Multisite Network has been rolled back. Now, WPO365 will display an access-denied splash screen instead, notifying the user of the denied access. If the user has already authenticated successfully, the screen will also show a list of sites where they have do privileges. [LOGIN]
- BREAKING CHANGE WPO365 will no longer redirect a user back to the login page of the site they requested in a WordPress Multisite Network when they do not have privileges to access that site. Instead WPO365 will display an access-denied splash screen, notifying the user of the denied access. If the user has already authenticated successfully, the screen will also show a list of sites where they do have privileges. [LOGIN]
- IMPROVEMENT The Calendar app (to embed an Exchange / Outlook Calendar in WordPress) can now be configured to show the personal calendar of the logged-in user. The tutorial has been updated accordingly. [APPS, INTEGRATE (INTRANET)]
- IMPROVEMENT The plugin can now also secure the WordPress REST API using App Roles / application-level access tokens (obtained using the client-credentials flow). The documentation has been updated support for this scenario. [ESSENTIALS, PROFESSIONAL, INTEGRATE (LOGIN+, SYNC, INTRANET)]
- IMPROVEMENT Users that are able to bypass SSO for the login page – by adding the secret key to the URL – are now also able to request a password-reset link and reset their password accordingly. [ESSENTIALS, PROFESSIONAL, CUSTOMERS, INTEGRATE (LOGIN+, SYNC, INTRANET)]
- IMPROVEMENT Administrators can now configure WPO365 to use a user’s email username as the domain for a new (WordPress Multisite) network subsite (instead of the user’s stringified WP User ID). [ESSENTIALS, PROFESSIONAL, CUSTOMERS, INTEGRATE (LOGIN+, SYNC, INTEGRATE)]
- FIX The favicon.ico file will now automatically be added to the list of pages freed from authentication, since – on WordPress Multisite – a user may request this file from the main site where the user does not have any privileges. [LOGIN]
- FIX The plugin will now also redirect users attempting to access the login page when the administrator has enabled SSO for the login page and the user is already logged in. [ESSENTIALS, PROFESSIONAL, CUSTOMERS, INTEGRATE (LOGIN+, SYNC, INTRANET)]
- FIX WPO365 now will remove any duplicate slashes from the current request URI, to prevent attackers to bypass – for example – SSO when it’s forced for the login page. [LOGIN]
- FIX The powerbi-client package has been updated to its latest version. [LOGIN, APPS, INTEGRATE (INTRANET)]
- FIX Fixed a string-format error that caused a critical error when the option to “Create new users in WordPress” would have been unchecked. [ALL PREMIUM]
- FIX The TLD “lan” has been added to the license-checker list of exceptions. [LOGIN, MSGRAPHMAILER]
- FIX “WPO365 Audiences” checkboxes on the Users, Posts and Pages screens in WP Admin now again are being displayed correctly. [ROLES + ACCESS, PROFESSIONAL, INTEGRATE (SYNC, INTRANET)]
- FIX An issue causing – under specific circumstances – an “array-to-string conversion” warning in the Url_Helpers class has been resolved. [LOGIN, MSGRAPHMAILER]
Click here for older entries.