CVE-2026-9615: Flex Import <= 3.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via 'license_activate_fleximp' and 'license_deactivate_fleximp' AJAX Actions

Published Sep 19, 2026
·
Updated

The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0. This is due to the licenseactivatefleximp() and licensedeactivatefleximp() functions, hooked to the wpajaxlicenseactivatefleximp and wpajaxlicensedeactivatefleximp AJAX actions, lacking both a capability check (currentusercan()) and nonce verification (the client-side script sends a 'wpnonce' value but the handlers never validate it). This makes it possible for authenticated attackers, with subscriber-level access and above, to activate an arbitrary/fraudulent license key (persisting it via updateoption('fleximpispremium') and toggling validation, suspension, and bundle status options) or deactivate the site's legitimate license (deleting the stored key and setting fleximpvalidationstatus to false), thereby disrupting the plugin's premium functionality.

Affected Software

1 affected component
WordPress plugin Flex Import<=3.0

Event History

Sep 19, 2026
CVE Published
via MITRE·07:43 AM
Data Sourced
via MITRE·07:43 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated WordPress user with Subscriber-level access or higher can invoke the affected AJAX actions. No administrator privileges or user interaction are required.

2

What can an attacker change?

An attacker can activate an arbitrary or fraudulent Flex Import license key, altering the plugin's premium, validation, suspension, and bundle-status options. They can also deactivate the legitimate license by deleting its stored key and setting the validation status to false, disrupting premium functionality.

3

Are nonce protections sufficient to prevent exploitation?

No. Although the client-side script sends a wpnonce value, the affected handlers do not verify it. They also do not perform a WordPress capability check.

4

What versions are affected?

All Flex Import versions up to and including 3.0 are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203