CyberRota Analysis
AI-GeneratedThe Import and Export Users and Customers plugin for WordPress versions prior to 2.5.2 is vulnerable due to improper enforcement of the promote_users capability during CSV imports, allowing users with only the create_users capability to escalate privileges by creating new administrator accounts or promoting existing users. This flaw poses a significant security risk as it can lead to unauthorized access and control over the WordPress site. WordPress administrators and security teams should prioritize updating this plugin to mitigate potential exploitation.
Original NVD Description
The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users capability to create new administrator accounts or promote existing users to administrator.