Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Binesh Madharapu

#23352of 57,243
11.3Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-95914
4.1
2026-09-20
WordPress · Export/Import Users/Customers · CVE-2026-16542
**Name of the Vulnerable Software and Affected Versions** Import and export users and customers WordPress plugin versions prior to 2.4.5 **Description** High-privileged users can perform Server-Side Request Forgery (SSRF) attacks during a CSV import. This occurs because the plugin fails to validate a user-supplied URL before the server requests it. **Recommendations** Update the plugin to version 2.4.5 or later.
PT-2026-95931
7.2
2026-09-20
WordPress · Export/Import Users/Customers · CVE-2026-92541
**Name of the Vulnerable Software and Affected Versions** Import and export users and customers versions prior to 2.5.2 **Description** Insufficient enforcement of the `promote users` capability within the front-end import functionality allows users who possess only the `create users` capability to modify the roles of existing users, which can lead to privilege escalation to the administrator role. **Recommendations** Update to version 2.5.2 or later.