{"id":"CVE-2026-15958","published":"2026-08-04T07:16:29.257","lastModified":"2026-08-04T18:16:45.220","description":"The Easy Integration for Dropbox  WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and upload arbitrary files across the connected Dropbox account and to read the connected account and administrator email addresses.","cvssScore":9.3,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N","cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/e424157e-b79f-4000-8dcc-51413581fdec/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated attackers to list, download, and upload files across the connected Dropbox account, and read connected account and administrator email addresses, due to missing authorization checks in the Easy Integration for Dropbox WordPress plugin before 2.2.0.","exploitability":"Exploitation is relatively straightforward as the flaw affects unauthenticated users, and no specific conditions are required other than access to the affected plugin.","blast_radius":"If exploited, the impact could be significant, as it allows full control over the connected Dropbox account and access to sensitive information like email addresses.","remediation":"Upgrade to version 2.2.0 or later of the Easy Integration for Dropbox WordPress plugin.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","file-management","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T09:05:21.694Z"}}