CVE-2026-92541

NONE EPSS 0.13%
Updated Sep 20, 2026
Unknown
Parameter Value
Affected Versions before 2.5.2
Type CWE-269 Improper Privilege Management
Vendor Unknown
Public PoC No

The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator.

Vulnerable Products

unknown:import and export users and customers