PT-2026-65431 · Eazyplugins · Eazy Plugin Manager – Powerful Plugin Management Solution For Wordpress
CVE-2026-14328
·
Publicado
2026-07-28
·
Atualizado
2026-07-28
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.1. This is due to insufficient authorization on the
wp ajax pos get option AJAX handler, which verifies only a nonce that is localized to every logged-in admin-area user via admin enqueue scripts — without any capability check — before returning the value of any arbitrary WordPress option via get option(), combined with the admin login endpoint handler REST endpoint (GET /wp-json/epm/v1/admin/login) being registered as publicly accessible and authenticating callers solely by a whirlpool hash of values stored in those same options. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the site url, connection key, and remote user id values stored in the eazywp connecting info and eazywp connection options, compute the required auth key, call the admin/login REST endpoint to obtain Administrator authentication cookies, and fully take over the site. Exploitation requires the plugin's remote connection feature to have been configured, as the eazywp connecting info and eazywp connection options must be populated with valid credentials.Correção
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Eazy Plugin Manager – Powerful Plugin Management Solution For Wordpress