PT-2026-67112 · WordPress · Export/Import Users/Customers

·

CVE-2026-16534

·

Published

2026-08-03

·

Updated

2026-08-03

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Import and export users and customers versions prior to 2.4.2
Description The plugin fails to enforce role-assignment and per-user edit permissions during the CSV import process. This allows a user with only the capability to create users to escalate their privileges by creating an administrator account or overwriting the password or email of an existing administrator.
Recommendations Update to version 2.4.2 or later.

Exploit

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16534

Affected Products

Export/Import Users/Customers