Description
Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions.
Published: 2026-08-20
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WordPress EPROLO Dropshipping plugin versions up to 2.4.2 contain an unauthenticated broken access‑control flaw identified as CWE‑862. An attacker can send crafted requests to the plugin’s endpoints without authenticating and gain administrative privileges, potentially modifying configuration, injecting content, or altering the dropshipping workflow. This loss of authorization can compromise site integrity and data.

Affected Systems

The vulnerability affects the EPROLO Dropshipping plugin from vendor paulepro2019, specifically all releases dated 2.4.2 or earlier. WordPress sites that have installed any of these versions are vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of these metrics does not reduce the risk posed by an unauthenticated flaw. The attack vector is inferred to be remote over the network; an attacker only needs to target the plugin’s endpoints, bypassing any login checks. Consequently, any publicly accessible WordPress installation with the vulnerable plugin is at risk of privilege escalation and can be exploited without prior authentication.

Generated by OpenCVE AI on August 20, 2026 at 22:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the EPROLO Dropshipping plugin to version 2.4.3 or later where the access‑control flaw is fixed.
  • If an immediate update is not feasible, disable the plugin until the patch is applied to eliminate the attack surface.
  • Apply WordPress hardening best practices, such as enforcing least privilege, using a security plugin to limit login attempts, and restricting administrative access to trusted IPs.

Generated by OpenCVE AI on August 20, 2026 at 22:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Paulepro2019
Paulepro2019 eprolo Dropshipping
Wordpress
Wordpress wordpress
Vendors & Products Paulepro2019
Paulepro2019 eprolo Dropshipping
Wordpress
Wordpress wordpress

Thu, 20 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions.
Title WordPress EPROLO Dropshipping plugin <= 2.4.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Paulepro2019 Eprolo Dropshipping
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-24T13:01:25.744Z

Reserved: 2026-08-14T10:16:17.543Z

Link: CVE-2026-74019

cve-icon Vulnrichment

Updated: 2026-08-24T12:55:30.984Z

cve-icon NVD

Status : Deferred

Published: 2026-08-20T12:16:37.567

Modified: 2026-08-24T14:16:59.380

Link: CVE-2026-74019

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:09:38Z

Weaknesses