Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 20 Sep 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 CWE-640 |
Sun, 20 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 | |
| Metrics |
cvssV3_1
|
Sun, 20 Sep 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 CWE-640 |
Sun, 20 Sep 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator. | |
| Title | Import and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Administrator via Frontend Importer | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-20T13:52:18.349Z
Reserved: 2026-09-16T12:58:16.942Z
Link: CVE-2026-92541
Updated: 2026-09-20T13:51:28.232Z
Status : Deferred
Published: 2026-09-20T07:16:51.353
Modified: 2026-09-21T13:34:57.127
Link: CVE-2026-92541
No data.
OpenCVE Enrichment
Updated: 2026-09-20T18:30:03Z