PT-2026-97604 · WordPress · Export/Import Users/Customers

·

CVE-2026-86583

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Import and export users and customers plugin for WordPress versions prior to 2.4.18
Description An issue exists in the export and re-import workflow that allows authenticated users with Subscriber-level access or higher to escalate their privileges to Administrator. The problem occurs because the exporter uses fputcsv() with a NUL byte as the escape character, while the importer uses SplFileObject::fgetcsv() with default PHP backslash escape characters. By crafting specific values in the display name and nickname profile fields, an attacker can cause the parser to merge the display name cell into the role field during import. This results in the add role() function assigning the administrator role to the attacker's account. Exploitation requires a site administrator to perform an export and re-import migration with both Update existing users and Update roles for existing users enabled.
Recommendations Update the plugin to a version newer than 2.4.17.

Fix

LPE

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86583

Affected Products

Export/Import Users/Customers