---
id: CVE-2026-87842
title: >-
  The Zonify  WordPress plugin before 1.0.5 does not perform any capability or
  authentication check before returning the site's stored account login token,
  allowing unauthenticated attackers to retrieve it and authenticate to the site
  owne…
summary: >-
  The Zonify  WordPress plugin before 1.0.5 does not perform any capability or
  authentication check before returning the site's stored account login token,
  allowing unauthenticated attackers to retrieve it and authenticate to the site
  owne…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
product: Zonify
affected:
  - Zonify < 1.0.5
published: '2026-09-12'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T21:10:17.423'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-87842'
references:
  - url: 'https://wpscan.com/vulnerability/fb0cafdc-d1d5-4cad-852e-b0d569ae4469/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00496
epssPercentile: 0.40078
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-12T15:16:44.842713Z'
ingestedAt: '2026-09-14T15:23:07.479Z'
---

## Overview

The Zonify  WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked service account.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
