CVE-2026-12240
HIGHExport User Data <= 2.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary File Deletion via display_name Field
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-12240. PoCs published by HermesNA-1.
AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-12240, a WordPress Export User Data plugin vulnerability allowing arbitrary file deletion via insufficient path validation in the unserialize function. The code includes placeholder logic but lacks actual exploit implementation.
Description
The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unserialize function in all versions up to, and including, 2.2.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Successful exploitation requires an administrator to trigger a user data export while a subscriber-level (or higher) user has stored a crafted serialized XLSXWriter object payload as their display name.
Exploits (1)
This repository contains an auto-generated stub module for CVE-2026-12240, a WordPress Export User Data plugin vulnerability allowing arbitrary file deletion via insufficient path validation in the unserialize function. The code includes placeholder logic but lacks actual exploit implementation.
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H