WPO365 45.0 Security Update: Action Required

WPO365 45.0 Security Update is now available and is one of the most important security releases to date.

This release addresses multiple security vulnerabilities, strengthens how WPO365 interacts with Microsoft Graph, removes several legacy and less secure configuration options, and introduces additional safeguards designed to protect your WordPress website, Microsoft 365 environment, and your users.

It is strongly recommend that all customers update both their free and premium WPO365 plugins to version 45.0 as soon as possible.

After Updating: Complete These Three Steps

1. Update all WPO365 plugins

Ensure that both the free WPO365 plugin and every installed premium add-on have been updated to the latest version.

2. Run the WPO365 Self-Test

After the update, navigate to WP Admin > WPO365 > Dashboard and run the WPO365 Self-Test.

The self-test verifies that your Microsoft 365 integration, authentication configuration, permissions, and plugin settings are working correctly after the upgrade.

3. Review WPO365 Health Messages

Next, review the WPO365 Health Messages available at WP Admin > WPO365 > Dashboard > WPO365 Health Messages.

Version 45.0 introduces additional validation checks that can identify:

  • Unsupported or deprecated configurations
  • Security-related configuration concerns
  • Configuration changes required because of breaking changes in version 45.0
  • Potential compatibility issues that may affect apps, authentication, or Microsoft Graph access

Please review and resolve all warnings and recommendations shown in the dashboard.

Why This Update Matters

Version 45.0 includes fixes and hardening measures for several security-related issues, including authentication validation, Microsoft Graph endpoint protection, application permission controls, token handling, error disclosure, and cross-site scripting (XSS) protection.

Some previously supported options have been removed or replaced because they no longer meet general security standards. As a result, websites that continue to run older versions may remain exposed to known risks or rely on configurations that are no longer considered secure.

Update all WPO365 plugins to version 45.0, run the Self-Test, and review the WPO365 Health Messages to ensure your environment remains secure, supported, and fully operational.