PT-2026-65431 · Eazyplugins · Eazy Plugin Manager – Powerful Plugin Management Solution For Wordpress

CVE-2026-14328

·

Publicado

2026-07-28

·

Atualizado

2026-07-28

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.1. This is due to insufficient authorization on the wp ajax pos get option AJAX handler, which verifies only a nonce that is localized to every logged-in admin-area user via admin enqueue scripts — without any capability check — before returning the value of any arbitrary WordPress option via get option(), combined with the admin login endpoint handler REST endpoint (GET /wp-json/epm/v1/admin/login) being registered as publicly accessible and authenticating callers solely by a whirlpool hash of values stored in those same options. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the site url, connection key, and remote user id values stored in the eazywp connecting info and eazywp connection options, compute the required auth key, call the admin/login REST endpoint to obtain Administrator authentication cookies, and fully take over the site. Exploitation requires the plugin's remote connection feature to have been configured, as the eazywp connecting info and eazywp connection options must be populated with valid credentials.

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-14328

Produtos afetados

Eazy Plugin Manager – Powerful Plugin Management Solution For Wordpress