Dropbox integration exposes unauthenticated account-wide file management
Easy Integration for Dropbox before 2.2.0 registers several file-management AJAX actions for unauthenticated callers without authorization checks. An attacker can list, download and upload arbitrary files throughout the connected Dropbox account and disclose the connected account and administrator email addresses. The public advisory does not disclose the AJAX action names, path or file parameters, upload field or callbacks.
- Component
- Easy Integration for Dropbox
- Plugin slug
easy-integration-for-dropbox- Affected
- < 2.2.0
- Safe version
2.2.0- Published
- Aug 04, 2026
- Weakness
- CWE-862 — Missing Authorization
This CVE was published Aug 04, 2026 and is one of 1 known issue for this plugin.
Update, patch or deactivate.
Update Easy Integration for Dropbox to 2.2.0 or later. Revoke and replace the connected Dropbox credential, review account-wide file history for unauthorized reads or writes and remove attacker-uploaded content.
A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.
Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.
Technical description
The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and upload arbitrary files across the connected Dropbox account and to read the connected account and administrator email addresses.
CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N