What is CVE-2026-17515?
CVE-2026-17515 is a critical vulnerability in the "MLSImport: IDX Plugin & MLS Plugin for Real Estate" WordPress plugin. Due to missing authorization and CSRF checks in one of its AJAX actions, any authenticated user, such as a subscriber, can read the plugin's content in versions prior to 7.0.4. Users are strongly advised to update the plugin to at least version 7.0.4 to mitigate the issue.
Azərbaycanca: CVE-2026-17515, "MLSImport: IDX Plugin & MLS Plugin for Real Estate" adlı WordPress plaginində aşkar edilmiş kritik zəiflikdir. 7.0.4 versiyasından əvvəlki versiyalarda bir AJAX əməliyyatında avtorizasiya və CSRF yoxlamalarının olmaması səbəbindən, "subscriber" kimi aşağı səviyyəli autentifikasiya olunmuş istənilən istifadəçi plagin məlumatlarının məzmununu oxuya bilər. Bu zəiflikdən qorunmaq üçün istifadəçilərə plaqini ən azı 7.0.4 versiyasına yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which WordPress plugin is affected by CVE-2026-17515?
This vulnerability affects the "MLSImport: IDX Plugin & MLS Plugin for Real Estate" plugin.
To which version should the plugin be updated to mitigate CVE-2026-17515?
Users are advised to update the plugin to at least version 7.0.4.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.