Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Khanhnv

#32408of 57,418
8.8Total CVSS
Vulnerabilities · 1
PT-2026-97604
8.8
2026-09-23
WordPress · Export/Import Users/Customers · CVE-2026-86583
**Name of the Vulnerable Software and Affected Versions** Import and export users and customers plugin for WordPress versions prior to 2.4.18 **Description** An issue exists in the export and re-import workflow that allows authenticated users with Subscriber-level access or higher to escalate their privileges to Administrator. The problem occurs because the exporter uses `fputcsv()` with a NUL byte as the escape character, while the importer uses `SplFileObject::fgetcsv()` with default PHP backslash escape characters. By crafting specific values in the `display name` and `nickname` profile fields, an attacker can cause the parser to merge the `display name` cell into the role field during import. This results in the `add role()` function assigning the administrator role to the attacker's account. Exploitation requires a site administrator to perform an export and re-import migration with both Update existing users and Update roles for existing users enabled. **Recommendations** Update the plugin to a version newer than 2.4.17.