Sceawere

Vulnerability Detail

CVE-2026-74019UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

EPROLO Dropshipping Broken Access Control

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
6h ago
Vendor
paulepro2019
Product
EPROLO Dropshipping
Attack Type
CWE-862 Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-08-20T12:16:37.567Z",
  "pubdate": "2026-08-20T12:16:37.567Z",
  "executiveSummary": "An unauthenticated broken access control vulnerability has been identified in the EPROLO Dropshipping plugin for versions 2.4.2 and below. This security flaw allows unauthenticated remote attackers to bypass authorization checks and interact with restricted functionalities or access sensitive data exposed by the affected component. The risk implications are severe, as unauthorized actors can exploit this weakness without requiring credentials or prior system access, potentially leading to unauthorized data exposure, state modifications, or administrative function execution depending on the specific endpoints exposed by the vulnerable plugin. The attack capability is fully remote, leveraging standard web protocols to target exposed application interfaces. Remediation requires updating the EPROLO Dropshipping product to a patched version beyond 2.4.2 as soon as vendor advisories and updates become available.",
  "technicalDetails": "The vulnerability resides in the access control implementation of the EPROLO Dropshipping plugin for versions <= 2.4.2. The root cause stems from missing or inadequate authorization checks on sensitive backend functions or AJAX actions exposed to the web layer, allowing unauthenticated users to invoke privileged methods directly.\nNetwork exposure is inherent to the HTTP/HTTPS interface of the web application hosting the vulnerable WordPress plugin. Because the affected endpoints fail to validate the session state, privilege level, or cryptographic nonces associated with the requesting entity, any remote attacker can craft direct HTTP requests targeting these exposed routines.\nThe attack flow proceeds as follows: First, the attacker identifies the exposed handler or endpoint associated with the EPROLO Dropshipping functionality via source code analysis or automated scanning. Second, the attacker formulates a malicious HTTP request (GET or POST) containing the parameters required by the vulnerable function. Third, because the underlying code lacks proper capability checks (such as current_user_can() validation) or role-based access control, the application processes the input and executes the requested operation on behalf of the unauthenticated entity.\nThe affected component involves the request-handling logic within the EPROLO Dropshipping codebase where administrative or backend routines are improperly exposed without session enforcement. Authentication requirements are entirely absent, and zero privileges are needed to trigger the flaw. Post-exploitation impact varies based on the specific capabilities exposed by the vulnerable functions, potentially resulting in unauthorized configuration changes, data leakage, or further compromise of the underlying content management system."
}
CVE-2026-74019: EPROLO Dropshipping Broken Access Control (HIGH Severity, CVSS: 7.1) - Sceawere