WordPress · Export/Import Users/Customers · CVE-2026-86583
**Name of the Vulnerable Software and Affected Versions**
Import and export users and customers plugin for WordPress versions prior to 2.4.18
**Description**
An issue exists in the export and re-import workflow that allows authenticated users with Subscriber-level access or higher to escalate their privileges to Administrator. The problem occurs because the exporter uses `fputcsv()` with a NUL byte as the escape character, while the importer uses `SplFileObject::fgetcsv()` with default PHP backslash escape characters. By crafting specific values in the `display name` and `nickname` profile fields, an attacker can cause the parser to merge the `display name` cell into the role field during import. This results in the `add role()` function assigning the administrator role to the attacker's account. Exploitation requires a site administrator to perform an export and re-import migration with both Update existing users and Update roles for existing users enabled.
**Recommendations**
Update the plugin to a version newer than 2.4.17.