MEDIUM
flextheme
CVE published 2026-09-19
CVE-2026-9615
The Flex Import plugin for WordPress has a Missing Authorization vulnerability in all versions up to, and including, 3.0. This allows authenticated attackers with subscriber-level access and above to activate arbitrary or fraudulent license keys or deactivate the site's legitimate license, disrupting premium functionality. The vulnerability is due to the license_activate_fleximp() and license_deactivate_f [truncated]