What is CVE-2026-15958?
The Easy Integration for Dropbox WordPress plugin before 2.2.0 lacks authorization checks on several file-management AJAX actions registered for unauthenticated users. This allows an attacker to list, download, and upload arbitrary files on a site connected to Dropbox. Update the plugin to the latest version immediately or disable it as a temporary measure.
Azərbaycanca: Easy Integration for Dropbox WordPress plaginində (2.2.0-dən əvvəl) autentifikasiya olunmamış istifadəçilər üçün fayl idarəetmə AJAX əməliyyatlarında avtorizasiya çatışmazlığı aşkarlanıb. Bu boşluq hücumçuya Dropbox-a qoşulmuş saytda icazəsiz fayl siyahılama, endirmə və yükləmə imkanı verir. Plagin dərhal ən son versiyaya yenilənməli və ya müvəqqəti olaraq deaktiv edilməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Easy Integration for Dropbox plugin are affected by CVE-2026-15958?
The vulnerability affects all versions of the plugin before 2.2.0.
What unauthorized operations can an attacker perform by exploiting CVE-2026-15958?
An attacker can perform unauthorized file listing, downloading, and uploading operations on a site connected to Dropbox.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.