


Perceptive Security
SOC/SIEM Consultancy

The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV im…
Published:
3 August 2026 at 00:00:00
Alert date:
3 August 2026 at 20:04:46
Source:
nvd.nist.gov
Web Technologies, Identity & Access
A vulnerability in the 'Import and export users and customers' WordPress plugin before version 2.4.2 allows privilege escalation through CSV import functionality. The plugin fails to enforce WordPress role-assignment and per-user edit permissions during CSV imports. A low-privileged user with only user-creation capability can exploit this flaw to create administrator accounts. Additionally, the vulnerability allows overwriting existing administrator passwords or email addresses. This effectively enables account takeover of administrator accounts. The issue has been patched in version 2.4.2 of the plugin.
Technical details
Mitigation steps:
Affected products:
Import and export users and customers WordPress plugin < 2.4.2
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-16534
https://wpscan.com/vulnerability/0d1246a0-3cd1-4b6d-bd3e-6ed89745da26/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
