Impact
The Flex Import plugin for WordPress is vulnerable to a missing authorization check in the AJAX handlers for license activation and deactivation. Because the functions license_activate_fleximp() and license_deactivate_fleximp() lack both a capability check (current_user_can()) and nonce verification, any authenticated user with at least subscriber level privilege can trigger these actions. The attacker can therefore inject arbitrary or fraudulent license keys, toggle validation, suspension, and bundle status options, or delete the stored license key, disrupting the plugin’s premium functionality. This flaw is identified as a CWE‑862, Missing Authorization.
Affected Systems
WordPress sites running Flex Import plugin version 3.0 or earlier are impacted. Reference code usage has been confirmed in the 2.5 and 2.8 release tracks, but the issue exists in all released versions up to 3.0. The product is distributed by the vendor flextheme under the Flex Import name.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests very low current exploitation probability. The flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to have a valid authenticated WordPress account with subscriber or higher capability; no further privileges or pre‑exploitation steps are required. Given the authentication requirement and low exploit likelihood, the practical risk to most sites is moderate, but any site that relies on the plugin’s premium features should immediately address the authorization gap.
OpenCVE Enrichment