← WordPress Vulnerabilities
WordPress security by component

Eazy Plugin Manager

Eazy Plugin Manager is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Jul 28, 2026; the highest CVE/CNA score is 9.9.

Plugin slug: plugins-on-steroids

CVE-2026-14328: Eazy Plugin Manager subscribers can escalate to Administrator

Eazy Plugin Manager through 4.4.1 allows any authenticated Subscriber to call wp_ajax_pos_get_option because the handler checks only a nonce localized to every logged-in admin-area user and performs no capability check. When the remote connection feature is configured, the attacker can read site_url, connection_key and remote_user_id from the eazywp_connecting_info and eazywp_connection options, derive the required whirlpool auth_key, and submit it to the public GET /wp-json/epm/v1/admin/login endpoint. admin_login_endpoint_handler then returns Administrator authentication cookies, enabling full site takeover. The CNA record does not disclose the request parameter used to select the option. No fixed public release is identified, and the WordPress.org plugin entry is closed.

PublishedJul 28, 2026
Safe version guidanceSee mitigation notes
Safe version
Jul 28, 2026 CVE-2026-14328
Eazy Plugin Manager subscribers can escalate to Administrator
Eazy Plugin Manager through 4.4.1 allows any authenticated Subscriber to call wp_ajax_pos_get_option because the handler checks only a nonce localized to every logged-in admin-area user and performs no capability check. When the remote connection feature is configured, the attacker can read site_url, connection_key and remote_user_id from the eazywp_connecting_info and eazywp_connection options, derive the required whirlpool auth_key, and submit it to the public GET /wp-json/epm/v1/admin/login endpoint. admin_login_endpoint_handler then returns Administrator authentication cookies, enabling full site takeover. The CNA record does not disclose the request parameter used to select the option. No fixed public release is identified, and the WordPress.org plugin entry is closed.
See mitigation notes
CVE8.8
NVDPending
Apr 11, 2025 CVE-2025-32542
Eazy Plugin Manager: A security weakness
Eazy Plugin Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.8
NVDPending
Apr 25, 2024 CVE-2023-51482
Eazy Plugin Manager: A security weakness
Eazy Plugin Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.9
NVDPending