PatchSiren

flextheme CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM flextheme CVE published 2026-09-19

CVE-2026-9615

The Flex Import plugin for WordPress has a Missing Authorization vulnerability in all versions up to, and including, 3.0. This allows authenticated attackers with subscriber-level access and above to activate arbitrary or fraudulent license keys or deactivate the site's legitimate license, disrupting premium functionality. The vulnerability is due to the license_activate_fleximp() and license_deactivate_f [truncated]