WordPress · Export/Import Users/Customers · CVE-2026-92541
**Name of the Vulnerable Software and Affected Versions**
Import and export users and customers versions prior to 2.5.2
**Description**
Insufficient enforcement of the `promote users` capability within the front-end import functionality allows users who possess only the `create users` capability to modify the roles of existing users, which can lead to privilege escalation to the administrator role.
**Recommendations**
Update to version 2.5.2 or later.