CVE-2026-87842 UNKNOWN

CVE-2026-87842

Published: 2026-09-12

Description

The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked service account.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…