A vulnerability categorized as critical has been discovered in eazyplugins Eazy Plugin Manager Plugin up to 4.4.1 on WordPress. This impacts the function
wp_ajax_pos_get_option/admin_login_endpoint_handler of the file /wp-json/epm/v1/admin/login of the component AJAX Handler/REST Endpoint. The manipulation of the argument site_url/connection_key/remote_user_id results in improper authorization.
This vulnerability is reported as CVE-2026-14328. The attack can be launched remotely. No exploit exists.