CVE-2026-87842 - Zonify < 1.0.5 - Unauthenticated Account Login Token Disclosure
CVE ID :CVE-2026-87842
Published : Sept. 12, 2026, 6:16 a.m. | 4 hours, 50 minutes ago
Description :The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked service account.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 12, 2026, 6:16 a.m. | 4 hours, 50 minutes ago
Description :The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked service account.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...