Description
The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0. This is due to the license_activate_fleximp() and license_deactivate_fleximp() functions, hooked to the wp_ajax_license_activate_fleximp and wp_ajax_license_deactivate_fleximp AJAX actions, lacking both a capability check (current_user_can()) and nonce verification (the client-side script sends a 'wpnonce' value but the handlers never validate it). This makes it possible for authenticated attackers, with subscriber-level access and above, to activate an arbitrary/fraudulent license key (persisting it via update_option('fleximp_is_premium') and toggling validation, suspension, and bundle status options) or deactivate the site's legitimate license (deleting the stored key and setting fleximp_validation_status to false), thereby disrupting the plugin's premium functionality.
Published: 2026-09-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: License Tampering
Action: Immediate Patch
AI Analysis

Impact

The Flex Import plugin for WordPress is vulnerable to a missing authorization check in the AJAX handlers for license activation and deactivation. Because the functions license_activate_fleximp() and license_deactivate_fleximp() lack both a capability check (current_user_can()) and nonce verification, any authenticated user with at least subscriber level privilege can trigger these actions. The attacker can therefore inject arbitrary or fraudulent license keys, toggle validation, suspension, and bundle status options, or delete the stored license key, disrupting the plugin’s premium functionality. This flaw is identified as a CWE‑862, Missing Authorization.

Affected Systems

WordPress sites running Flex Import plugin version 3.0 or earlier are impacted. Reference code usage has been confirmed in the 2.5 and 2.8 release tracks, but the issue exists in all released versions up to 3.0. The product is distributed by the vendor flextheme under the Flex Import name.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests very low current exploitation probability. The flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to have a valid authenticated WordPress account with subscriber or higher capability; no further privileges or pre‑exploitation steps are required. Given the authentication requirement and low exploit likelihood, the practical risk to most sites is moderate, but any site that relies on the plugin’s premium features should immediately address the authorization gap.

Generated by OpenCVE AI on September 19, 2026 at 23:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available update from the vendor that addresses the missing authorization and nonce checks for license activate/deactivate AJAX actions.
  • If an immediate update is unavailable, modify the plugin’s license activation/deactivation functions to enforce a capability check such as current_user_can('manage_options') and verify the provided nonce using check_admin_referer('fleximp_license_action', 'wpnonce').
  • After applying a patch or code change, restrict the wp_ajax_license_activate_fleximp and wp_ajax_license_deactivate_fleximp hooks to administrators only by removing the subscriber‑level access or adding a capability requirement at the hook registration step.

Generated by OpenCVE AI on September 19, 2026 at 23:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Flextheme
Flextheme flex Import
Wordpress
Wordpress wordpress
Vendors & Products Flextheme
Flextheme flex Import
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description The Flex Import plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.0. This is due to the license_activate_fleximp() and license_deactivate_fleximp() functions, hooked to the wp_ajax_license_activate_fleximp and wp_ajax_license_deactivate_fleximp AJAX actions, lacking both a capability check (current_user_can()) and nonce verification (the client-side script sends a 'wpnonce' value but the handlers never validate it). This makes it possible for authenticated attackers, with subscriber-level access and above, to activate an arbitrary/fraudulent license key (persisting it via update_option('fleximp_is_premium') and toggling validation, suspension, and bundle status options) or deactivate the site's legitimate license (deleting the stored key and setting fleximp_validation_status to false), thereby disrupting the plugin's premium functionality.
Title Flex Import <= 3.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via 'license_activate_fleximp' and 'license_deactivate_fleximp' AJAX Actions
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Flextheme Flex Import
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:25.429Z

Reserved: 2026-05-26T16:31:06.724Z

Link: CVE-2026-9615

cve-icon Vulnrichment

Updated: 2026-09-19T13:55:47.990Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T08:16:55.193

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-9615

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:03:43Z

Weaknesses