WordPress · Export/Import Users/Customers · CVE-2026-92540
**Name of the Vulnerable Software and Affected Versions**
Import and export users and customers versions prior to 2.5.2
**Description**
Insufficient enforcement of the `promote users` capability during CSV imports allows users who possess only the `create users` capability to create new administrator accounts or elevate existing users to the administrator role.
**Recommendations**
Update Import and export users and customers to version 2.5.2 or later.