CVE-2026-12240

HIGH

Export User Data <= 2.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary File Deletion via display_name Field

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-12240. PoCs published by HermesNA-1.

AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-12240, a WordPress Export User Data plugin vulnerability allowing arbitrary file deletion via insufficient path validation in the unserialize function. The code includes placeholder logic but lacks actual exploit implementation.

Description

The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unserialize function in all versions up to, and including, 2.2.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Successful exploitation requires an administrator to trigger a user data export while a subscriber-level (or higher) user has stored a crafted serialized XLSXWriter object payload as their display name.

Exploits (1)

github STUB 1 stars
by HermesNA-1 · pythonpoc
https://github.com/HermesNA-1/SnakeSploit/tree/main/data/modules_generated/cve-2026-12240_the_export_user.py

This repository contains an auto-generated stub module for CVE-2026-12240, a WordPress Export User Data plugin vulnerability allowing arbitrary file deletion via insufficient path validation in the unserialize function. The code includes placeholder logic but lacks actual exploit implementation.

Classification
Stub 99%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: WordPress Export User Data plugin <= 2.2.6
No auth needed
Prerequisites: Target must have vulnerable plugin version installed · Network access to WordPress instance
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →

Scores

CVSS v3 8.0
EPSS 0.0033
EPSS Percentile 25.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-502
Status published
Products (1)
qlstudio/Export User Data < 2.2.6
Published Jun 30, 2026
Tracked Since Jun 30, 2026