PT-2026-67653 · WordPress · Easy Integration For Dropbox
CVE-2026-15958
·
Published
2026-08-04
·
Updated
2026-08-04
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Easy Integration for Dropbox WordPress plugin versions prior to 2.2.0
Description
Insufficient authorization checks on several file-management AJAX actions registered for unauthenticated users allow an unauthenticated attacker to list, download, and upload arbitrary files within the connected Dropbox account. Additionally, this flaw enables the disclosure of the connected account and administrator email addresses.
Recommendations
Update Easy Integration for Dropbox WordPress plugin to version 2.2.0 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Easy Integration For Dropbox