WordPress security by component
Easy Integration for Dropbox
Easy Integration for Dropbox (easy-integration-for-dropbox) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 04, 2026; the highest published CVSS base score is 9.3.
Plugin slug:
easy-integration-for-dropboxLatest vulnerability
CVE-2026-15958: Dropbox integration exposes unauthenticated account-wide file management
Easy Integration for Dropbox before 2.2.0 registers several file-management AJAX actions for unauthenticated callers without authorization checks. An attacker can list, download and upload arbitrary files throughout the connected Dropbox account and disclose the connected account and administrator email addresses. The public advisory does not disclose the AJAX action names, path or file parameters, upload field or callbacks.
| Safe version |
|
||
|---|---|---|---|
| Aug 04, 2026 |
CVE-2026-15958
Dropbox integration exposes unauthenticated account-wide file management
Easy Integration for Dropbox before 2.2.0 registers several file-management AJAX actions for unauthenticated callers without authorization checks. An attacker can list, download and upload arbitrary files throughout the connected Dropbox account and disclose the connected account and administrator email addresses. The public advisory does not disclose the AJAX action names, path or file parameters, upload field or callbacks.
|
2.2.0 |
CVE9.3
NVDPending
|