PT-2026-65431 · Eazyplugins · Eazy Plugin Manager – Powerful Plugin Management Solution For Wordpress

CVE-2026-14328

·

Published

2026-07-28

·

Updated

2026-07-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.1. This is due to insufficient authorization on the wp ajax pos get option AJAX handler, which verifies only a nonce that is localized to every logged-in admin-area user via admin enqueue scripts — without any capability check — before returning the value of any arbitrary WordPress option via get option(), combined with the admin login endpoint handler REST endpoint (GET /wp-json/epm/v1/admin/login) being registered as publicly accessible and authenticating callers solely by a whirlpool hash of values stored in those same options. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the site url, connection key, and remote user id values stored in the eazywp connecting info and eazywp connection options, compute the required auth key, call the admin/login REST endpoint to obtain Administrator authentication cookies, and fully take over the site. Exploitation requires the plugin's remote connection feature to have been configured, as the eazywp connecting info and eazywp connection options must be populated with valid credentials.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14328

Affected Products

Eazy Plugin Manager – Powerful Plugin Management Solution For Wordpress