← WordPress Vulnerabilities
WordPress security by component

zonify

zonify is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 7.5.

Plugin slug: zonify

CVE-2026-87842: Zonify discloses its linked-service login token

Zonify before 1.0.5 returns the site's stored linked-account login token without authentication or a capability check. An unauthenticated attacker can retrieve the token and authenticate to the site owner's linked service account. The authoritative export does not identify the endpoint, response field, token scope, or linked service.

PublishedSep 12, 2026
Known safe version1.0.5
Published vulnerabilities for zonify
Safe version
Sep 12, 2026 CVE-2026-87842
Zonify discloses its linked-service login token
Zonify before 1.0.5 returns the site's stored linked-account login token without authentication or a capability check. An unauthenticated attacker can retrieve the token and authenticate to the site owner's linked service account. The authoritative export does not identify the endpoint, response field, token scope, or linked service.
1.0.5
CVE7.5
NVDPending