PT-2026-65431 · WordPress · Eazy Plugin Manager

CVE-2026-14328

·

Published

2026-07-28

·

Updated

2026-07-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Eazy Plugin Manager versions prior to 4.4.2
Description Insufficient authorization in the wp ajax pos get option AJAX handler allows authenticated users with Subscriber-level access or higher to retrieve the value of any arbitrary WordPress option via the get option() function. This occurs because the handler only verifies a nonce without performing a capability check. When combined with the publicly accessible admin login endpoint handler REST endpoint (GET /wp-json/epm/v1/admin/login), which authenticates users using a whirlpool hash of specific option values, an attacker can read the site url, connection key, and remote user id from the eazywp connecting info and eazywp connection options. By computing the auth key from these values, an attacker can call the admin/login endpoint to obtain Administrator authentication cookies and gain full control of the site. This issue requires the remote connection feature to be configured with valid credentials in the mentioned options.
Recommendations Update Eazy Plugin Manager to version 4.4.2 or later. As a temporary mitigation, disable the remote connection feature to ensure the eazywp connecting info and eazywp connection options are not populated.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14328

Affected Products

Eazy Plugin Manager