Impact
The Easy Integration for Dropbox plugin fails to perform authorization checks on several file‑management AJAX actions that are available to unauthenticated users. When exploited, an attacker can list, download, and upload arbitrary files to the connected Dropbox account and read the account’s email address and the site administrator’s email address. This enables full compromise of the data stored in the linked Dropbox account and offers a vector for uploading malicious content that could harm the site or the user’s environment.
Affected Systems
Any WordPress site that installs the Easy Integration for Dropbox plugin in a version earlier than 2.2.0. Versions 2.2.0 and newer are not affected as per the vendor’s release notes.
Risk and Exploitability
The vulnerability can be exploited by an unauthenticated attacker through the exposed nopriv AJAX endpoints, making the attack vector easy and low‑friction. The EPSS score of < 1 % indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV, but the absence of authentication checks implies a high risk of data exfiltration, unauthorized disclosure of account details, and the potential upload of malicious files. The CVSS score of 9.3 indicates critical severity.
OpenCVE Enrichment