File Management Vulnerability in Easy Integration for Dropbox WordPress Plugin
CVE-2026-15958

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
4 August 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-15958?

The Easy Integration for Dropbox plugin for WordPress prior to version 2.2.0 lacks proper authorization checks on its file-management AJAX actions. This oversight enables unauthenticated attackers to exploit the system, potentially allowing them to list, download, and upload arbitrary files across the compromised Dropbox account. Additionally, these vulnerabilities may grant access to the connected user's account details, including email addresses linked to the administrator, posing severe risks to data integrity and privacy.

Affected Version(s)

Easy Integration for Dropbox 0 < 2.2.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pablo González Pérez
Francisco José Ramírez Vicente and Iñigo Sánchez Enciso
WPScan
.