Ad

CVE-2026-92540

NONE EPSS 0.13%
Обновлено 20 сентября 2026
Unknown
Параметр Значение
Уязвимые версии до 2.5.2
Тип уязвимости CWE-269 Improper Privilege Management
Поставщик Unknown
Публичный эксплойт Нет

The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users capability to create new administrator accounts or promote existing users to administrator.

Тип уязвимости (CWE)

Уязвимые продукты

unknown:import and export users and customers