PT-2026-95796 · WordPress · Flex Import
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Flex Import versions prior to 3.1
Description
The plugin contains a missing authorization flaw. The
license activate fleximp() and license deactivate fleximp() functions, which are linked to the wp ajax license activate fleximp and wp ajax license deactivate fleximp AJAX actions, do not perform capability checks using current user can() or validate nonces. This allows authenticated users with subscriber-level access or higher to activate fraudulent license keys by modifying fleximp is premium via update option() or deactivate legitimate licenses by setting fleximp validation status to false, which disrupts premium features.Recommendations
Update to a version later than 3.0.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flex Import