CVE-2026-92541: Unknown Import And Export Users And Customers

High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.

The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator.

Affected products

  • Unknown Import And Export Users And Customers: before 2.5.2 (fixed in 2.5.2)

Published 2026-09-20. Last modified 2026-09-21.