CVE-2026-104757: WordPress Import and export users and customers plugin <= 2.5.5 - Privilege Escalation vulnerability
Published Oct 6, 2026
·Updated
Editor Privilege Escalation in Import and export users and customers <= 2.5.5 versions.
Affected Software
1 affected component
WordPress Import and export users and customers<=2.5.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Import and export users and customers pluginto a version that resolves this vulnerability.Fixed in 2.5.7
Event History
Oct 6, 2026
CVE Published
via MITRE·08:35 AM
Data Sourced
via MITRE·08:35 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
An attacker needs Editor-level privileges. The vector is network-accessible and does not require user interaction.
2
What could a successful attacker do?
The vulnerability is identified as a privilege escalation issue, with high impact to confidentiality, integrity, and availability.
3
Which plugin versions are affected?
Versions 2.5.5 and earlier of the WordPress Import and export users and customers plugin are affected.