Junglewise Threat Intelligence

CVE-2026-15026: carazo Import and export users and customers sensitive information exposure

CVE-2026-15026 · Severity: medium · CVSS 4.3 · Published 2026-07-10

Executive brief

A vulnerability in a popular WordPress plugin used for managing user data allows low-level users to view private information they should not be able to see. This includes sensitive data like WooCommerce orders, internal CRM records, and private drafts. An attacker with a basic account could use this to steal customer information or internal business documents.

Technical details

The 'Import and export users and customers' plugin for WordPress suffers from a missing authorization check (CWE-862) in the 'email_template_selected' functionality. Authenticated attackers with Subscriber-level permissions can obtain a required security nonce ('codection-security') which is improperly exposed as inline JavaScript on wp-admin pages when a specific query parameter is used. By leveraging this nonce and enumerating post IDs, an attacker can extract the 'post_title' and 'post_content' of any post type, including private WooCommerce orders, CRM records, and password-protected posts. The vulnerability is present in all versions up to and including 2.4.0.

Affected products

  • carazo Import and export users and customers up to, and including, 2.4.0

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory

References