WordPress Plugin Vulnerabilities

Easy Dropbox Integration < 2.2.0 - Unauthenticated Arbitrary Connected Dropbox File Access and Upload via nopriv AJAX

Description

The plugin does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and upload arbitrary files across the connected Dropbox account and to read the connected account and administrator email addresses.

Proof of Concept

Affects Plugins

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Pablo González Pérez, Francisco José Ramírez Vicente and Iñigo Sánchez Enciso
Submitter
Pablo González Pérez, Francisco José Ramírez Vicente and Iñigo Sánchez Enciso
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-07-27 (about 8 days ago)
Added
2026-07-27 (about 7 days ago)
Last Updated
2026-08-03 (about 9 hours ago)

Other