WordPress security changelog
CRITICAL CVE-2026-15958 Received

Dropbox integration exposes unauthenticated account-wide file management

Easy Integration for Dropbox before 2.2.0 registers several file-management AJAX actions for unauthenticated callers without authorization checks. An attacker can list, download and upload arbitrary files throughout the connected Dropbox account and disclose the connected account and administrator email addresses. The public advisory does not disclose the AJAX action names, path or file parameters, upload field or callbacks.

CVE / CNA score 9.3 CVSS 3.1 · 134c704f-9b21-4f2e-91b3-4a467353bcc0
NVD score Pending NVD has not published its own CVSS assessment.
Component
Easy Integration for Dropbox
Plugin slug
easy-integration-for-dropbox
Affected
< 2.2.0
Safe version
2.2.0
Published
Aug 04, 2026
Weakness
CWE-862 — Missing Authorization

This CVE was published Aug 04, 2026 and is one of 1 known issue for this plugin.

Update, patch or deactivate.

Update Easy Integration for Dropbox to 2.2.0 or later. Revoke and replace the connected Dropbox credential, review account-wide file history for unauthorized reads or writes and remove attacker-uploaded content.

A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.

Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.

Technical description

The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and upload arbitrary files across the connected Dropbox account and to read the connected account and administrator email addresses.

CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

Primary and upstream sources