The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator.
CVE-2026-92541
NONE
EPSS 0.13%
Updated Sep 20, 2026
Unknown
unknown:import and export users and customers
CVE Details
CVE ID
CVE-2026-92541
Published Date
Sep 20, 2026
Vendor
Unknown
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.13%
Likelihood of exploitation in next 30 days
Percentile:
3.2th percentile (higher than 3.2% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory