# CVE-2026-87842

## Summary

- **CVE ID:** CVE-2026-87842
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** N/A
- **Published:** Sep 12, 2026
- **Last Modified:** Sep 12, 2026

## Description

The Zonify  WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers to retrieve it and authenticate to the site owner's linked service account.

## Affected Products

- Unknown — Zonify (0)

## References

- [CNA](https://wpscan.com/vulnerability/fb0cafdc-d1d5-4cad-852e-b0d569ae4469/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.29%
- **EPSS Percentile:** 21.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._