Eazy Plugin Manager
Eazy Plugin Manager is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Jul 28, 2026; the highest CVE/CNA score is 9.9.
plugins-on-steroidsCVE-2026-14328: Eazy Plugin Manager subscribers can escalate to Administrator
Eazy Plugin Manager through 4.4.1 allows any authenticated Subscriber to call wp_ajax_pos_get_option because the handler checks only a nonce localized to every logged-in admin-area user and performs no capability check. When the remote connection feature is configured, the attacker can read site_url, connection_key and remote_user_id from the eazywp_connecting_info and eazywp_connection options, derive the required whirlpool auth_key, and submit it to the public GET /wp-json/epm/v1/admin/login endpoint. admin_login_endpoint_handler then returns Administrator authentication cookies, enabling full site takeover. The CNA record does not disclose the request parameter used to select the option. No fixed public release is identified, and the WordPress.org plugin entry is closed.
| Safe version |
|
||
|---|---|---|---|
| Jul 28, 2026 |
CVE-2026-14328
Eazy Plugin Manager subscribers can escalate to Administrator
Eazy Plugin Manager through 4.4.1 allows any authenticated Subscriber to call wp_ajax_pos_get_option because the handler checks only a nonce localized to every logged-in admin-area user and performs no capability check. When the remote connection feature is configured, the attacker can read site_url, connection_key and remote_user_id from the eazywp_connecting_info and eazywp_connection options, derive the required whirlpool auth_key, and submit it to the public GET /wp-json/epm/v1/admin/login endpoint. admin_login_endpoint_handler then returns Administrator authentication cookies, enabling full site takeover. The CNA record does not disclose the request parameter used to select the option. No fixed public release is identified, and the WordPress.org plugin entry is closed.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Apr 11, 2025 |
CVE-2025-32542
Eazy Plugin Manager: A security weakness
Eazy Plugin Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Apr 25, 2024 |
CVE-2023-51482
Eazy Plugin Manager: A security weakness
Eazy Plugin Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.9
NVDPending
|