CVE-2026-14328
eazyplugins Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress
The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.1. This is due to insufficient authorization on the `wp_ajax_pos_get_option` AJAX handler, which verifies only a nonce that is localized to every logged-in admin-area user via `admin_enqueue_scripts` — without any capability check — before returning the value of any arbitrary WordPress option via `get_option()`, combined with the `admin_login_endpoint_handler` REST endpoint (`GET /wp-json/epm/v1/admin/login`) being r...
- CVSS
- 8.8
- EPSS
- 0.38% 30.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.28