


Perceptive Security
SOC/SIEM Consultancy

The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it als…
Published:
4 augustus 2026 om 00:00:00
Alert date:
4 augustus 2026 om 21:04:59
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Data Breach & Exfiltration
CVE-2026-15958 affects the Easy Integration for Dropbox WordPress plugin before version 2.2.0. The plugin fails to perform authorization checks on several file-management AJAX actions that are registered for unauthenticated users. This allows unauthenticated attackers to list, download, and upload arbitrary files on the connected Dropbox account. Additionally, attackers can read the connected Dropbox account email address and the WordPress administrator email address. The vulnerability is a classic broken access control/missing authorization issue. No authentication is required to exploit this flaw, making it trivially exploitable by any remote attacker. WordPress site owners using this plugin should update to version 2.2.0 or later immediately.
Technical details
Mitigation steps:
Affected products:
Easy Integration for Dropbox WordPress plugin (before 2.2.0)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-15958
https://wpscan.com/vulnerability/e424157e-b79f-4000-8dcc-51413581fdec/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
