OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-92540

HIGH · CVSS 7.2 EPSS 0.46%

Source: NVD + CISA KEV + EPSS · Published 2026-09-20 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The Import and Export Users and Customers plugin for WordPress versions prior to 2.5.2 is vulnerable due to improper enforcement of the promote_users capability during CSV imports, allowing users with only the create_users capability to escalate privileges by creating new administrator accounts or promoting existing users. This flaw poses a significant security risk as it can lead to unauthorized access and control over the WordPress site. WordPress administrators and security teams should prioritize updating this plugin to mitigate potential exploitation.

CVE
CVE-2026-92540
Severity
HIGH
CVSS
7.2
EPSS
0.46%
WordPress

Original NVD Description

The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users capability to create new administrator accounts or promote existing users to administrator.