CVE-2026-16534
Received Received - Intake

Import and export users privilege escalation in WordPress plugin

Vulnerability report for CVE-2026-16534, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: WPScan

Description

The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
import_and_export_users_and_customers import_and_export_users_and_customers to 2.4.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Import and export users and customers WordPress plugin before version 2.4.2 allows a user with only user-creation capability to bypass WordPress's role-assignment and edit permissions during CSV import. This enables them to create an administrator account or overwrite an existing administrator's password or email.

Detection Guidance

Check if the Import and export users and customers WordPress plugin is installed and verify its version. If it is version 2.4.2 or lower, the system is vulnerable. Look for unexpected administrator accounts or changes to existing admin emails or passwords.

Impact Analysis

An attacker could gain full administrative control of a WordPress site by exploiting this flaw. This could lead to complete site takeover, data theft, unauthorized modifications, or disruption of services.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR's data protection requirements and HIPAA's security rules. It may result in legal penalties, loss of compliance certifications, and reputational damage.

Mitigation Strategies

Update the Import and export users and customers plugin to version 2.4.2 or higher immediately. Review all administrator accounts for unauthorized changes and remove any suspicious accounts. Reset passwords for all admin accounts as a precaution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16534. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart