CVE-2026-15958
9.3 CRITICALPublished 2026-08-04 · Updated 2026-08-04
AI risk analysis
- Summary
- The flaw allows unauthenticated attackers to list, download, and upload files across the connected Dropbox account, and read connected account and administrator email addresses, due to missing authorization checks in the Easy Integration for Dropbox WordPress plugin before 2.2.0.
- Exploitability
- Exploitation is relatively straightforward as the flaw affects unauthenticated users, and no specific conditions are required other than access to the affected plugin.
- Blast radius
- If exploited, the impact could be significant, as it allows full control over the connected Dropbox account and access to sensitive information like email addresses.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to version 2.2.0 or later of the Easy Integration for Dropbox WordPress plugin.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and upload arbitrary files across the connected Dropbox account and to read the connected account and administrator email addresses.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Weaknesses
CWE-862
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-100617PoC
- HIGHCVE-2026-16561
- HIGHCVE-2026-16605
- HIGHCVE-2026-17070
- HIGHCVE-2026-18650
- CRITICALCVE-2026-4431
- MEDIUMCVE-2026-48974PoC
- CRITICALCVE-2026-49994PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.