Impact
The Zonify WordPress plugin for versions before 1.0.5 fails to perform any capability or authentication check before returning the site's stored account login token. As a result, anyone who can reach the vulnerable endpoint can retrieve this token and authenticate to the site owner's linked service account. The vulnerability constitutes a confidentiality breach and is classified as CWE‑200.
Affected Systems
All installations of the Zonify plugin on WordPress sites that are using a version earlier than 1.0.5 are affected. This includes any WordPress site where the plugin is active, regardless of other themes or plugins. Based on the description, it is inferred that no other vendor or product information is relevant beyond the Zonify plugin.
Risk and Exploitability
The flaw can be exploited by anyone with internet access to the WordPress site, as no authentication is required. The CVSS score of 7.5 denotes high severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV. Attackers could use the disclosed token to gain sensitive data.
OpenCVE Enrichment