CVE Database /
CVE-2026-15026
CVE · Medium
CVE-2026-15026 — Import and export users and customers [import-users-from-csv-with-meta] < 2.4.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-15026
|
Import and export users and customers [import-users-from-csv-with-meta] < 2.4.1 |
Missing Authorization |
Medium
4.3
|
< 2.4.1
|
2.4.1 |
2026-05-01 |
—
|
CVE-2026-15026
A WordPress plugin called Import and export users and customers has a flaw that allows attackers with subscriber-level access or higher to obtain sensitive information from arbitrary posts, regardless of their status or type. This vulnerability exists in all versions up to 2.4.0 because the nonce required for exploiting it is inadvertently exposed as JavaScript code on certain wp-admin pages. By appending ?post_type=acui_email_template to a URL, any authenticated user can access this sensitive information.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings