Description
The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and upload arbitrary files across the connected Dropbox account and to read the connected account and administrator email addresses.
Published: 2026-08-04
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Easy Integration for Dropbox plugin fails to perform authorization checks on several file‑management AJAX actions that are registered for unauthenticated users. Consequently an attacker who can access the site can list, download, upload arbitrary files to the connected Dropbox account and read the account’s email address as well as the administrator’s email address. This allows a complete compromise of the information stored in the linked Dropbox account and provides a vector for uploading malicious content that could compromise the site or the user’s environment.

Affected Systems

Any WordPress site running the Easy Integration for Dropbox plugin in a version earlier than 2.2.0. Versions 2.2.0 and newer are not affected according to the vendor’s release notes.

Risk and Exploitability

The vulnerability can be leveraged by an unauthenticated attacker through the exposed nopriv AJAX endpoints, making the attack vector easy and low‑friction. No EPSS score is available, and the vulnerability is not listed in CISA KEV, but the absence of authentication checks implies a high risk of data exfiltration, unauthorized disclosure of account details, and potential upload of malicious files. The lack of a guarding access control means that any visitor can perform the privileged actions, so the impact is broad and unmitigated. The CVSS score is not provided, but the practical risk is considered high due to the ease of exploitation.

Generated by OpenCVE AI on August 4, 2026 at 09:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Easy Integration for Dropbox plugin to version 2.2.0 or later
  • If an update cannot be performed immediately, restrict the nopriv AJAX actions so that only authenticated users can invoke file‑management functions, which can be implemented by modifying the plugin settings or adding a small code patch
  • Revoke the current Dropbox API access token and generate a new token with minimal required scopes, ensuring that any compromised token cannot be reused
  • Monitor Dropbox activity logs for unexpected uploads or downloads and notify administrators of suspicious behavior

Generated by OpenCVE AI on August 4, 2026 at 09:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 04 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and upload arbitrary files across the connected Dropbox account and to read the connected account and administrator email addresses.
Title Easy Dropbox Integration < 2.2.0 - Unauthenticated Arbitrary Connected Dropbox File Access and Upload via nopriv AJAX
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-04T06:00:11.056Z

Reserved: 2026-07-16T13:56:06.858Z

Link: CVE-2026-15958

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T09:30:06Z

Weaknesses