e-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via API Token via 'eshot_form_builder_get_account_data' AJAX Action

2026-03-20 15:09
Poli

Strategic Overview

Status
Unpatched
Affected Plugine-shot
Affected Version<= 1.0.2
CVSS5.3Medium
CVECVE-2026-3546
View all e-shot vulnerabilities

Vulnerability Overview

The e-shot form builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.2. The eshot_form_builder_get_account_data() function is registered as a wp_ajax_ AJAX handler accessible to all authenticated users. The function lacks any capability check (e.g., current_user_can('manage_options')) and does not verify a nonce. It directly queries the database for the e-shot API token stored in the eshotformbuilder_control table and returns it along with all subaccount data as a JSON response. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract the e-shot API token and subaccount information, which could then be used to access the victim's e-shot platform account.

Technical Analysis

REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-202 (Exposure of Sensitive Information Through Data Queries) When trying to keep information confidential, an attacker can often infer some of the information by using statistics.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C