CVE-2026-16534

The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-03 07:16

Updated : 2026-08-26 16:31


NVD link : CVE-2026-16534

Mitre link : CVE-2026-16534

CVE.ORG link : CVE-2026-16534


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management