CVE-2026-17515 Details
Description
The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisation and CSRF checks in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the contents of the MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4's import log file as well as import-related metadata belonging to arbitrary posts.
A vulnerability exists in the MLSImport: IDX Plugin and MLS Plugin for Real Estate Listings WordPress plugin, affecting versions prior to 7.0.4. The issue arises because the plugin's AJAX actions lack proper authorization and Cross-Site Request Forgery (CSRF) protections. This flaw enables any authenticated user, such as a subscriber, to access the plugin's import log file and import-related metadata from arbitrary posts.
Users are advised to update the MLSImport: IDX Plugin and MLS Plugin for Real Estate Listings WordPress plugin to version 7.0.4 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 5, 2026CISA-ADP
Assessed Aug 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/8c8da95c-df83-4788-bcb2-ca924a60f909/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | CISA-ADP |
| CWE-352 | Cross-Site Request Forgery (CSRF) | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| MLSImport IDX Plugin | < 7.0.4 (semver) |
CPE
Remediation
| |
| MLSImport MLS Plugin | < 7.0.4 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | New CVE Received | [email protected] |
Volerion