CVE-2026-92540: Unknown Import And Export Users And Customers

High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.

The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users capability to create new administrator accounts or promote existing users to administrator.

Affected products

  • Unknown Import And Export Users And Customers: from 2.4.16, before 2.5.2 (fixed in 2.5.2)

Published 2026-09-20. Last modified 2026-09-21.