Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 05 Aug 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 |
Wed, 05 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-352 | |
| Metrics |
cvssV3_1
|
Wed, 05 Aug 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mlsimport
Mlsimport idx Plugin & Mls Plugin For Real Estate Listings Wordpress Wordpress wordpress |
|
| Vendors & Products |
Mlsimport
Mlsimport idx Plugin & Mls Plugin For Real Estate Listings Wordpress Wordpress wordpress |
Wed, 05 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 CWE-284 |
Wed, 05 Aug 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisation and CSRF checks in one of its AJAX actions, allowing any authenticated user, such as a subscriber, to read the contents of the MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4's import log file as well as import-related metadata belonging to arbitrary posts. | |
| Title | MLS Import < 7.0.4 - Subscriber+ Sensitive Information Disclosure via mlsimport_logger_per_item | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-05T13:54:29.194Z
Reserved: 2026-07-27T07:31:16.599Z
Link: CVE-2026-17515
Updated: 2026-08-05T13:54:11.486Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T17:45:16Z