Executive brief
EPROLO Dropshipping is a WordPress plugin used for managing dropshipping operations. A broken access control vulnerability allows unauthenticated users to access pages and perform actions they should not be authorized for, such as viewing other users' sensitive data. This could expose customer information, orders, or configuration details to unauthorized parties.
Technical details
The vulnerability is a broken access control flaw in the EPROLO Dropshipping WordPress plugin that allows unauthenticated attackers to bypass authorization checks and access restricted functionality or data. The vulnerability requires no user authentication and is network-accessible via the WordPress plugin interface. An attacker can access pages or perform actions restricted to authorized users, potentially leading to unauthorized data disclosure or account compromise. As of the advisory publication date, no official patch has been released; mitigation is recommended until an update is available.
Affected products
- EPROLO Dropshipping <=2.4.2
Timeline
- 2026-08-20: disclosed: CVE-2026-74019 published
- 2026-02-19: other: Reported by hivesec