CVE-2026-94178: WordPress Import and export users and customers plugin <= 2.5.2 - Privilege Escalation vulnerability
Subscriber Privilege Escalation in Import and export users and customers <= 2.5.2 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Import and export users and customers pluginto a version that resolves this vulnerability.Fixed in 2.5.4
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attack vector indicates that an attacker needs an existing low-privileged account. No user interaction is required once that access is available.
What could a successful exploit allow?
The vulnerability is rated as having high impact on confidentiality, integrity, and availability. It could enable privilege escalation from a subscriber-level account, potentially leading to broad compromise of the affected WordPress site.
Is a fixed plugin release identified?
The provided information identifies versions 2.5.2 and earlier as affected. It does not identify a release containing a fix.