CVE · Medium

CVE-2026-15026 — Import and export users and customers [import-users-from-csv-with-meta] < 2.4.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15026 Import and export users and customers [import-users-from-csv-with-meta] < 2.4.1 Missing Authorization Medium 4.3 < 2.4.1 2.4.1 2026-05-01

CVE-2026-15026

A WordPress plugin called Import and export users and customers has a flaw that allows attackers with subscriber-level access or higher to obtain sensitive information from arbitrary posts, regardless of their status or type. This vulnerability exists in all versions up to 2.4.0 because the nonce required for exploiting it is inadvertently exposed as JavaScript code on certain wp-admin pages. By appending ?post_type=acui_email_template to a URL, any authenticated user can access this sensitive information.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.