Impact
The Easy Integration for Dropbox plugin fails to perform authorization checks on several file‑management AJAX actions that are registered for unauthenticated users. Consequently an attacker who can access the site can list, download, upload arbitrary files to the connected Dropbox account and read the account’s email address as well as the administrator’s email address. This allows a complete compromise of the information stored in the linked Dropbox account and provides a vector for uploading malicious content that could compromise the site or the user’s environment.
Affected Systems
Any WordPress site running the Easy Integration for Dropbox plugin in a version earlier than 2.2.0. Versions 2.2.0 and newer are not affected according to the vendor’s release notes.
Risk and Exploitability
The vulnerability can be leveraged by an unauthenticated attacker through the exposed nopriv AJAX endpoints, making the attack vector easy and low‑friction. No EPSS score is available, and the vulnerability is not listed in CISA KEV, but the absence of authentication checks implies a high risk of data exfiltration, unauthorized disclosure of account details, and potential upload of malicious files. The lack of a guarding access control means that any visitor can perform the privileged actions, so the impact is broad and unmitigated. The CVSS score is not provided, but the practical risk is considered high due to the ease of exploitation.
OpenCVE Enrichment