PT-2026-95931 · WordPress · Export/Import Users/Customers

·

CVE-2026-92541

·

Published

2026-09-20

·

Updated

2026-09-20

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Import and export users and customers versions prior to 2.5.2
Description Insufficient enforcement of the promote users capability within the front-end import functionality allows users who possess only the create users capability to modify the roles of existing users, which can lead to privilege escalation to the administrator role.
Recommendations Update to version 2.5.2 or later.

Exploit

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92541

Affected Products

Export/Import Users/Customers