CyberRota Analysis
AI-GeneratedThe Import and Export Users and Customers plugin for WordPress versions prior to 2.5.2 is vulnerable due to a lack of enforcement of the promote_users capability, enabling users with only the create_users permission to elevate existing users' roles, potentially granting them administrative access. This vulnerability poses a significant risk to site security, as unauthorized users could gain elevated privileges. WordPress site administrators using this plugin should prioritize updating to version 2.5.2 or later to mitigate this risk.
Original NVD Description
The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator.