rootpwn

high · CVSS v3 7.2 · EPSS 0.00132

CVE-2026-92541

The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in…

Description

The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator.

Scores

Severity
high
CVSS v2
8.3
CVSS v3
7.2
CVSS v4
EPSS
0.00132

← All CVEs