OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-92541

HIGH · CVSS 7.2 EPSS 0.46%

Source: NVD + CISA KEV + EPSS · Published 2026-09-20 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The Import and Export Users and Customers plugin for WordPress versions prior to 2.5.2 is vulnerable due to a lack of enforcement of the promote_users capability, enabling users with only the create_users permission to elevate existing users' roles, potentially granting them administrative access. This vulnerability poses a significant risk to site security, as unauthorized users could gain elevated privileges. WordPress site administrators using this plugin should prioritize updating to version 2.5.2 or later to mitigate this risk.

CVE
CVE-2026-92541
Severity
HIGH
CVSS
7.2
EPSS
0.46%
WordPress

Original NVD Description

The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator.