CVE-2026-92540
Received Received - Intake

Imported User Role Escalation in WordPress Users & Customers Plugin

Vulnerability report for CVE-2026-92540, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-20

Last updated on: 2026-09-20

Assigner: WPScan

Description

The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users capability to create new administrator accounts or promote existing users to administrator.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-20
Last Modified
2026-09-20
Generated
2026-09-20
AI Q&A
2026-09-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Import and export users and customers WordPress plugin before version 2.5.2 allows users with only the create_users capability to escalate their privileges to administrator during a CSV import. The plugin fails to enforce the promote_users capability correctly when assigning roles.

Detection Guidance

Check the installed version of the 'Import and export users and customers' WordPress plugin. If it is version 2.5.2 or earlier, the system is vulnerable. Review user role assignments after CSV imports to detect unauthorized administrator promotions.

Impact Analysis

An attacker with the create_users capability could exploit this to create new administrator accounts or promote existing users to administrator. This could lead to full control of the WordPress site, unauthorized access, and potential data breaches or site defacement.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, which may violate GDPR and HIPAA requirements for data protection and access control. Non-compliance could result in legal penalties, fines, and reputational damage.

Mitigation Strategies

Update the 'Import and export users and customers' plugin to version 2.5.2 or later. Restrict the 'create_users' capability to trusted users only. Monitor user roles and privileges for unauthorized changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92540. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart