CVE detail
CVE-2026-15026
The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via the email_template_selected. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the post_title and raw post_content of arbitrary posts regardless of status (draft, private, future, trash, password-protected) or post type (including non-public CPTs such as WooCommerce orders and internal CRM records) by enumerating post IDs. The required codection-security nonce is exposed as inline JavaScript on any wp-admin page when ?post_type=acui_email_template is appended to the URL, which is reachable by any authenticated user including Subscribers.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 23.0 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
9 source links · newest first
- Wordfence Intelligence Weekly WordPress Vulnerability Report (July 6, 2026 to July 12, 2026)Wordfence
.26 - 4.1.15 - Missing Authorization to Unauthenticated Payment Bypass via REST API 5.3 CVSS Rating 5.3 (Medium) CVE-ID CVE-2026-13039 Patch Status Patched Published Jul 9, 2026 Affected Software Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] Researcher Niv Kochan More Details > Extra Product Options Builder
vendorwww.wordfence.comJul 16, 2026, 8:29 PM - https://www.wordfence.com/threat-intel/vulnerabilities/id/85b61e0f-3bb2-4688-b513-14f4d2da6c30?source=cvewww.wordfence.com
No excerpt available.
Patchwww.wordfence.comJul 10, 2026, 9:16 AM - https://plugins.trac.wordpress.org/changeset?reponame=&old=3601455%40import-users-from-csv-with-meta&new=3601455%40import-users-from-csv-with-metaplugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 10, 2026, 9:16 AM - https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta/tags/2.3.9/classes/email-templates.php#L96plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 10, 2026, 9:16 AM - https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta/tags/2.3.9/classes/email-templates.php#L9plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 10, 2026, 9:16 AM - https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta/tags/2.3.9/classes/email-options.php#L357plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 10, 2026, 9:16 AM - https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta/tags/2.0.10/classes/email-templates.php#L96plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 10, 2026, 9:16 AM - https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta/tags/2.0.10/classes/email-templates.php#L9plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 10, 2026, 9:16 AM - https://plugins.trac.wordpress.org/browser/import-users-from-csv-with-meta/tags/2.0.10/classes/email-options.php#L357plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 10, 2026, 9:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-66589CVSS 5.4 · Medium
Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects B2BKing: from n/a through…
- CVE-2026-53453CVSS 8.7 · High
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio exposed administrator-intended backend API actions to any a…
- CVE-2026-12631CVSS 6.5 · Medium
The Zephyr kernel validates the k_thread_join() and k_thread_abort() system calls (declared __syscall in include/zephyr/kernel.h) through thread_obj_validate() in kernel/thread.c.…
- CVE-2026-76032CVSS 5.3 · Medium
Pydio Cells 5.0.0 through 5.0.2 returns share-link details to any authenticated user. The REST handler for GET /a/share/link/{Uuid} in idm/share/rest/handler.go reads the workspac…
- CVE-2026-71322CVSS 4.3 · Medium
Lemur manages TLS certificate creation. Prior to 1.9.3, CertificateExport placed its CertificatePermission ownership check inside the plugin.requires_key branch for POST /api/1/ce…
- CVE-2026-71317CVSS 6.5 · Medium
Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/authorities with type=subca did not require AuthorityPermission on the parent authority when ADMIN_ONLY_AUTHORI…