top of page
perceptive_background_267k.jpg

The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it als…

Published:

4 augustus 2026 om 00:00:00

Alert date:

4 augustus 2026 om 21:04:59

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Data Breach & Exfiltration

CVE-2026-15958 affects the Easy Integration for Dropbox WordPress plugin before version 2.2.0. The plugin fails to perform authorization checks on several file-management AJAX actions that are registered for unauthenticated users. This allows unauthenticated attackers to list, download, and upload arbitrary files on the connected Dropbox account. Additionally, attackers can read the connected Dropbox account email address and the WordPress administrator email address. The vulnerability is a classic broken access control/missing authorization issue. No authentication is required to exploit this flaw, making it trivially exploitable by any remote attacker. WordPress site owners using this plugin should update to version 2.2.0 or later immediately.

Technical details

Mitigation steps:

Affected products:

Easy Integration for Dropbox WordPress plugin (before 2.2.0)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page