Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-15026— Import and export users and customers <= 2.4.0 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected AJAX Action

Quick assessment

Affected
carazo Import and export users and customers
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

carazo Import and export users and customers是carazo的数据导入导出功能。 carazo Import and export users and customers 2.4.0及之前版本存在授权问题漏洞,该漏洞源于通过email_template_selected参数导致敏感信息泄露,可能导致经过身份验证的攻击者(具有订阅者级别及以上访问权限)通过枚举帖子ID提取任意帖子的标题和原始内容。

CVSS 4.3 · Medium EPSS 0.39% · P30

Affected Version Matrix 1

VendorProduct Version RangeStatus
carazo Import and export users and customers ≤ 2.4.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-15026

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Import and export users and customers <= 2.4.0 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected AJAX Action
Source: CVE Program / CVE List V5
Vulnerability Description
The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via the email_template_selected. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract the post_title and raw post_content of arbitrary posts regardless of status (draft, private, future, trash, password-protected) or post type (including non-public CPTs such as WooCommerce orders and internal CRM records) by enumerating post IDs. The required codection-security nonce is exposed as inline JavaScript on any wp-admin page when ?post_type=acui_email_template is appended to the URL, which is reachable by any authenticated user including Subscribers.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5
Vulnerability Title
carazo Import and export users and customers 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
carazo Import and export users and customers是carazo的数据导入导出功能。 carazo Import and export users and customers 2.4.0及之前版本存在授权问题漏洞,该漏洞源于通过email_template_selected参数导致敏感信息泄露,可能导致经过身份验证的攻击者(具有订阅者级别及以上访问权限)通过枚举帖子ID提取任意帖子的标题和原始内容。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
carazo Import and export users and customers 0 ~ 2.4.0 -

II. Public POCs for CVE-2026-15026

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-15026

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-15026 (4)

Vendor Advisories for CVE-2026-15026 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-15026

No comments yet


Leave a comment