WP Clinic
Log in Sign up

CVE · Medium

CVE-2026-15026 — Import and export users and customers [import-users-from-csv-with-meta] < 2.4.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15026 Import and export users and customers [import-users-from-csv-with-meta] < 2.4.1 Missing Authorization Medium 4.3 < 2.4.1 2.4.1 2026-07-09

CVE-2026-15026

The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via the email_template_selected. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the post_title and raw post_content of arbitrary posts regardless of status (draft, private, future, trash, password-protected) or post type (including non-public CPTs such as WooCommerce orders and internal CRM records) by enumerating post IDs. The required codection-security nonce is exposed as inline JavaScript on any wp-admin page when ?post_type=acui_email_template is appended to the URL, which is reachable by any authenticated user including Subscribers.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.