CVE-2026-74019: WordPress EPROLO Dropshipping plugin <= 2.4.2 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress EPROLO Dropshipping pluginto a version that resolves this vulnerability.Fixed in 2.4.2 - Configuration
Update the EPROLO Dropshipping plugin to a version later than 2.4.2 to remediate the unauthenticated broken access control vulnerability.
WordPress EPROLO Dropshipping plugin broken access control = mitigate by updating
Event History
Frequently Asked Questions
What level of access does an attacker need?
The provided data is inconsistent: the description calls the issue unauthenticated, while the CVSS vector assigns Privileges Required: Low. It does not clarify whether an account is actually needed.
What is the expected impact if exploitation succeeds?
The CVSS vector indicates high confidentiality impact and low integrity impact. It indicates no availability impact and no user interaction requirement.
How can I identify potentially affected installations?
Installations using the EPROLO Dropshipping plugin at version 2.4.2 or earlier are identified as affected. The provided data does not state a fixed version or workaround.