CVE-2026-17515
Received Received - Intake

Unauthenticated Log File Read in MLSImport WordPress Plugin

Vulnerability report for CVE-2026-17515, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: WPScan

Description

The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisation and CSRF checks in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the contents of the MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4's import log file as well as import-related metadata belonging to arbitrary posts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
mls_import mls_import_wordpress_plugin to 7.0.4 (exc)
mlsimport idx_plugin to 7.0.4 (exc)
mlsimport mls_plugin to 7.0.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the MLS Import WordPress plugin versions before 7.0.4. It allows any authenticated user, including low-privilege users like subscribers, to access sensitive data due to missing authorization and CSRF checks in an AJAX action. This flaw enables reading the plugin's import log file and import-related metadata for arbitrary posts.

Detection Guidance

Check if the MLS Import WordPress plugin version is below 7.0.4. Look for unauthorized access to import logs or metadata in plugin files or database entries. Monitor for unusual AJAX requests to the vulnerable endpoint.

Impact Analysis

An attacker could exploit this to read sensitive log files and metadata, potentially exposing confidential information about real estate listings or user activities. This could lead to data breaches or unauthorized access to proprietary data.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA by exposing personal or sensitive data. GDPR requires protection of personal data, while HIPAA mandates safeguards for health-related information. A breach could result in legal penalties or reputational damage.

Mitigation Strategies

Update the MLS Import WordPress plugin to version 7.0.4 or later immediately. Remove unnecessary user roles like subscribers if they are not required. Implement additional authorization checks for sensitive plugin actions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17515. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart