SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16534

CRITICAL · CVSS 9.1 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

The Import and Export Users and Customers plugin for WordPress versions prior to 2.4.2 is vulnerable due to inadequate enforcement of role-assignment and per-user edit permissions during CSV imports. This flaw allows users with only user-creation capabilities to escalate their privileges by creating an administrator account or overwriting an existing administrator's credentials. WordPress site administrators and security teams should prioritize updating this plugin to mitigate the risk of unauthorized access and potential compromise.

CVE
CVE-2026-16534
Severity
CRITICAL
CVSS
9.1
EPSS
0.23%
WordPress

Original NVD Description

The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email.