← WordPress Vulnerabilities
WordPress security by component

Easy Integration for Dropbox

Easy Integration for Dropbox (easy-integration-for-dropbox) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 04, 2026; the highest published CVSS base score is 9.3.

Plugin slug: easy-integration-for-dropbox

CVE-2026-15958: Dropbox integration exposes unauthenticated account-wide file management

Easy Integration for Dropbox before 2.2.0 registers several file-management AJAX actions for unauthenticated callers without authorization checks. An attacker can list, download and upload arbitrary files throughout the connected Dropbox account and disclose the connected account and administrator email addresses. The public advisory does not disclose the AJAX action names, path or file parameters, upload field or callbacks.

PublishedAug 04, 2026
Known safe version2.2.0
Published vulnerabilities for easy-integration-for-dropbox
Safe version
Aug 04, 2026 CVE-2026-15958
Dropbox integration exposes unauthenticated account-wide file management
Easy Integration for Dropbox before 2.2.0 registers several file-management AJAX actions for unauthenticated callers without authorization checks. An attacker can list, download and upload arbitrary files throughout the connected Dropbox account and disclose the connected account and administrator email addresses. The public advisory does not disclose the AJAX action names, path or file parameters, upload field or callbacks.
2.2.0
CVE9.3
NVDPending