PT-2026-65431 · WordPress · Eazy Plugin Manager
CVE-2026-14328
·
Published
2026-07-28
·
Updated
2026-07-28
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Eazy Plugin Manager versions prior to 4.4.2
Description
Insufficient authorization in the
wp ajax pos get option AJAX handler allows authenticated users with Subscriber-level access or higher to retrieve the value of any arbitrary WordPress option via the get option() function. This occurs because the handler only verifies a nonce without performing a capability check. When combined with the publicly accessible admin login endpoint handler REST endpoint (GET /wp-json/epm/v1/admin/login), which authenticates users using a whirlpool hash of specific option values, an attacker can read the site url, connection key, and remote user id from the eazywp connecting info and eazywp connection options. By computing the auth key from these values, an attacker can call the admin/login endpoint to obtain Administrator authentication cookies and gain full control of the site. This issue requires the remote connection feature to be configured with valid credentials in the mentioned options.Recommendations
Update Eazy Plugin Manager to version 4.4.2 or later.
As a temporary mitigation, disable the remote connection feature to ensure the
eazywp connecting info and eazywp connection options are not populated.Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eazy Plugin Manager