PT-2026-57118 · WordPress · Export/Import Users/Customers

·

CVE-2026-15026

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Import and export users and customers plugin for WordPress versions prior to 2.4.1
Description Authenticated users with subscriber-level access and above can extract the post title and raw post content of arbitrary posts by enumerating post IDs. This exposure affects posts regardless of their status (draft, private, future, trash, password-protected) or post type, including non-public Custom Post Types (CPTs) such as internal CRM records and WooCommerce orders. The issue occurs via the email template selected parameter. The necessary codection-security nonce is exposed as inline JavaScript on any wp-admin page when ?post type=acui email template is appended to the URL.
Recommendations Update the plugin to a version newer than 2.4.0.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15026

Affected Products

Export/Import Users/Customers