WordPress security by component
zonify
zonify is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 7.5.
Plugin slug:
zonifyLatest vulnerability
CVE-2026-87842: Zonify discloses its linked-service login token
Zonify before 1.0.5 returns the site's stored linked-account login token without authentication or a capability check. An unauthenticated attacker can retrieve the token and authenticate to the site owner's linked service account. The authoritative export does not identify the endpoint, response field, token scope, or linked service.
| Safe version |
|
||
|---|---|---|---|
| Sep 12, 2026 |
CVE-2026-87842
Zonify discloses its linked-service login token
Zonify before 1.0.5 returns the site's stored linked-account login token without authentication or a capability check. An unauthenticated attacker can retrieve the token and authenticate to the site owner's linked service account. The authoritative export does not identify the endpoint, response field, token scope, or linked service.
|
1.0.5 |
CVE7.5
NVDPending
|