top of page
perceptive_background_267k.jpg

The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV im…

Published:

2 August 2026 at 22:00:00

Alert date:

3 August 2026 at 18:04:46

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

A vulnerability in the 'Import and export users and customers' WordPress plugin before version 2.4.2 allows privilege escalation through CSV import functionality. The plugin fails to enforce WordPress role-assignment and per-user edit permissions during CSV imports. A low-privileged user with only user-creation capability can exploit this flaw to create administrator accounts. Additionally, the vulnerability allows overwriting existing administrator passwords or email addresses. This effectively enables account takeover of administrator accounts. The issue has been patched in version 2.4.2 of the plugin.

Technical details

Mitigation steps:

Affected products:

Import and export users and customers WordPress plugin < 2.4.2

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page