CVE-2026-87842
Received Received - Intake

Unauthenticated Account Token Exposure in Zonify WordPress Plugin

Vulnerability report for CVE-2026-87842, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-12

Last updated on: 2026-09-12

Assigner: WPScan

Description

The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked service account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-12
Last Modified
2026-09-12
Generated
2026-09-12
AI Q&A
2026-09-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zonify wordpress_plugin to 1.0.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Zonify WordPress plugin before version 1.0.5 has a flaw where it does not verify user permissions or require authentication before providing the stored account login token. This allows unauthenticated attackers to retrieve the token and use it to authenticate to the site owner's linked service account.

Detection Guidance

Check if the Zonify WordPress plugin version is below 1.0.5. Inspect network traffic for unauthenticated requests to endpoints returning login tokens. Use tools like WPScan to scan for vulnerable versions.

Impact Analysis

Unauthenticated attackers could gain access to your linked service account by exploiting this vulnerability. This could lead to unauthorized actions, data breaches, or misuse of your account, potentially compromising sensitive information or services tied to your WordPress site.

Compliance Impact

This vulnerability could lead to unauthorized access and exposure of sensitive data, which may violate compliance requirements under GDPR, HIPAA, or other regulations. It increases the risk of data breaches and unauthorized disclosures, potentially resulting in legal penalties or reputational damage.

Mitigation Strategies

Update the Zonify plugin to version 1.0.5 or later immediately. If an update is unavailable, consider disabling the plugin until a patch is released. Review and restrict access to sensitive endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87842. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart