CVE-2026-87842
—Unauthenticated Token Disclosure in Zonify WordPress Plugin Before 1.0.5
The Zonify WordPress plugin before version 1.0.5 fails to perform any capability or authentication check on the functionality that returns the site's stored account login token. An unauthenticated remote attacker can send a request to the affected endpoint and directly receive the token the site uses to connect to the owner's linked service account. With that token, the attacker can authenticate to the linked service as the site owner, gaining access to that connected account (CVSS 3.1: 7.5, high confidentiality impact with no privileges or user interaction required). Any WordPress site running Zonify prior to 1.0.5 is affected. The flaw is not in CISA's KEV catalog and there is no known public proof of concept or observed exploitation to date.
What to do: Upgrade Zonify to version 1.0.5 or later immediately. Because the stored token could already have been harvested, re-authorize the plugin to revoke and replace the linked service token, and review the linked account for unauthorized sessions or activity. If the plugin is no longer needed, remove it entirely, and check access logs for unauthenticated requests hitting the plugin's endpoints.
| Zonify (WordPress plugin) | before 1.0.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked service account.
- Ecosystems
- WordPress
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.