CVE-2026-16534: Import and export users and customers < 2.4.2 - Custom Role Privilege Escalation to Administrator via CSV Import
The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16534?
CVE-2026-16534 has a critical severity level with a CVSS score of 9.1.
How do I fix CVE-2026-16534?
To fix CVE-2026-16534, update the Import and export users and customers WordPress plugin to version 2.4.2 or later.
What is the impact of CVE-2026-16534?
CVE-2026-16534 allows an unauthorized user to escalate their privileges to that of an administrator via CSV import.
Who is affected by CVE-2026-16534?
Any WordPress site using the Import and export users and customers plugin version prior to 2.4.2 is affected by CVE-2026-16534.
What does CVE-2026-16534 exploit?
CVE-2026-16534 exploits the lack of enforcement of role-assignment and per-user edit permissions during CSV imports.