AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-15958

UNKNOWN · CVSS N/A EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-04

CyberRota Analysis

AI-Generated

The Easy Integration for Dropbox WordPress plugin versions prior to 2.2.0 lacks proper authorization checks for its file-management AJAX actions, which are accessible to unauthenticated users. This vulnerability allows attackers to list, download, and upload arbitrary files to the connected Dropbox account, as well as access sensitive information such as account and administrator email addresses. WordPress site administrators using this plugin should prioritize updating to version 2.2.0 or later to mitigate the risk of unauthorized access and data exposure.

CVE
CVE-2026-15958
Severity
UNKNOWN
CVSS
N/A
EPSS
0.14%
WordPress

Original NVD Description

The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and upload arbitrary files across the connected Dropbox account and to read the connected account and administrator email addresses.