CVE-2026-17515: MLS Import < 7.0.4 - Subscriber+ Sensitive Information Disclosure via mlsimport_logger_per_item
The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisation and CSRF checks in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the contents of the MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4's import log file as well as import-related metadata belonging to arbitrary posts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17515?
The severity of CVE-2026-17515 is rated at 45, indicating a moderate risk level.
How do I fix CVE-2026-17515?
To fix CVE-2026-17515, update the MLS Import: IDX Plugin & MLS Plugin for Real Estate Listings to version 7.0.4 or later.
What does CVE-2026-17515 exploit?
CVE-2026-17515 exploits the lack of authorization and CSRF checks in an AJAX action within the MLSImport plugin.
Who is affected by CVE-2026-17515?
Any authenticated user, including subscribers of the MLS Import plugin, can be affected by CVE-2026-17515.
What information can be disclosed due to CVE-2026-17515?
CVE-2026-17515 allows authenticated users to read sensitive information from the MLSImport: IDX Plugin & MLS Plugin for Real Estate.