PT-2026-97604 · WordPress · Export/Import Users/Customers
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Import and export users and customers plugin for WordPress versions prior to 2.4.18
Description
An issue exists in the export and re-import workflow that allows authenticated users with Subscriber-level access or higher to escalate their privileges to Administrator. The problem occurs because the exporter uses
fputcsv() with a NUL byte as the escape character, while the importer uses SplFileObject::fgetcsv() with default PHP backslash escape characters. By crafting specific values in the display name and nickname profile fields, an attacker can cause the parser to merge the display name cell into the role field during import. This results in the add role() function assigning the administrator role to the attacker's account. Exploitation requires a site administrator to perform an export and re-import migration with both Update existing users and Update roles for existing users enabled.Recommendations
Update the plugin to a version newer than 2.4.17.
Fix
LPE
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Export/Import Users/Customers