{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-15958", "assignerOrgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81", "state": "PUBLISHED", "assignerShortName": "WPScan", "dateReserved": "2026-07-16T13:56:06.858Z", "datePublished": "2026-08-04T06:00:11.056Z", "dateUpdated": "2026-08-04T17:36:26.194Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81", "shortName": "WPScan", "dateUpdated": "2026-08-04T06:00:11.056Z" }, "title": "Easy Dropbox Integration < 2.2.0 - Unauthenticated Arbitrary Connected Dropbox File Access and Upload via nopriv AJAX", "problemTypes": [ { "descriptions": [ { "description": "CWE-862 Missing Authorization", "lang": "en", "type": "CWE" } ] } ], "affected": [ { "vendor": "Unknown", "product": "Easy Integration for Dropbox", "versions": [ { "status": "affected", "versionType": "semver", "version": "0", "lessThan": "2.2.0" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and upload arbitrary files across the connected Dropbox account and to read the connected account and administrator email addresses." } ], "references": [ { "url": "https://wpscan.com/vulnerability/e424157e-b79f-4000-8dcc-51413581fdec/", "tags": [ "exploit", "vdb-entry", "technical-description" ] } ], "credits": [ { "lang": "en", "value": "Pablo González Pérez", "type": "finder" }, { "lang": "en", "value": "Francisco José Ramírez Vicente and Iñigo Sánchez Enciso", "type": "finder" }, { "lang": "en", "value": "WPScan", "type": "coordinator" } ], "source": { "discovery": "EXTERNAL" }, "x_generator": { "engine": "WPScan CVE Generator" } }, "adp": [ { "problemTypes": [ { "descriptions": [ { "type": "CWE", "cweId": "CWE-862", "lang": "en", "description": "CWE-862 Missing Authorization" } ] } ], "metrics": [ { "cvssV3_1": { "scope": "CHANGED", "version": "3.1", "baseScore": 9.3, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N", "integrityImpact": "LOW", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH" } }, { "other": { "type": "ssvc", "content": { "timestamp": "2026-08-04T17:36:02.206656Z", "id": "CVE-2026-15958", "options": [ { "Exploitation": "none" }, { "Automatable": "yes" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-08-04T17:36:26.194Z" } } ] } }