Description
The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and upload arbitrary files across the connected Dropbox account and to read the connected account and administrator email addresses.
Published: 2026-08-04
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Easy Integration for Dropbox plugin fails to perform authorization checks on several file‑management AJAX actions that are available to unauthenticated users. When exploited, an attacker can list, download, and upload arbitrary files to the connected Dropbox account and read the account’s email address and the site administrator’s email address. This enables full compromise of the data stored in the linked Dropbox account and offers a vector for uploading malicious content that could harm the site or the user’s environment.

Affected Systems

Any WordPress site that installs the Easy Integration for Dropbox plugin in a version earlier than 2.2.0. Versions 2.2.0 and newer are not affected as per the vendor’s release notes.

Risk and Exploitability

The vulnerability can be exploited by an unauthenticated attacker through the exposed nopriv AJAX endpoints, making the attack vector easy and low‑friction. The EPSS score of < 1 % indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV, but the absence of authentication checks implies a high risk of data exfiltration, unauthorized disclosure of account details, and the potential upload of malicious files. The CVSS score of 9.3 indicates critical severity.

Generated by OpenCVE AI on August 4, 2026 at 22:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Easy Integration for Dropbox plugin to version 2.2.0 or newer.
  • If an update cannot be performed immediately, restrict the nopriv AJAX actions so that only authenticated users can invoke file‑management functions, which can be implemented by modifying the plugin settings or adding a small code patch.
  • Revoke the current Dropbox API access token and generate a new token with minimal required scopes, ensuring that any compromised token cannot be reused.
  • Monitor Dropbox activity logs for unexpected uploads or downloads and notify administrators of suspicious behavior.

Generated by OpenCVE AI on August 4, 2026 at 22:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 04 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 04 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and upload arbitrary files across the connected Dropbox account and to read the connected account and administrator email addresses.
Title Easy Dropbox Integration < 2.2.0 - Unauthenticated Arbitrary Connected Dropbox File Access and Upload via nopriv AJAX
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-04T17:36:26.194Z

Reserved: 2026-07-16T13:56:06.858Z

Link: CVE-2026-15958

cve-icon Vulnrichment

Updated: 2026-08-04T17:36:21.158Z

cve-icon NVD

Status : Received

Published: 2026-08-04T07:16:29.257

Modified: 2026-08-04T18:16:45.220

Link: CVE-2026-15958

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T22:45:03Z

Weaknesses