{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awordpressimport_and_export_users_and_customers/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:import_and_export_users_and_customers:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-86583"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Import and export users and customers (\u003c= 2.4.17)"],"_cs_severities":["high"],"_cs_tags":["wordpress","privilege-escalation","web-application-security","cve-2026-86583"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Import and export users and customers plugin for WordPress (versions 2.4.17 and earlier) contains a privilege escalation vulnerability (CVE-2026-86583). The vulnerability stems from an inconsistency in how the plugin handles CSV escaping. The exporter utilizes fputcsv() with a NUL byte (\\0) as an escape character, while the importer utilizes SplFileObject::fgetcsv() with a default backslash escape character.\u003c/p\u003e\n\u003cp\u003eBecause the CSV column layout places the 'display_name' field immediately before the 'role' field and the 'nickname' field immediately after, a malicious user can craft specific values in their profile settings. When an administrator triggers a site-wide user export and subsequent re-import with \u0026quot;Update existing users\u0026quot; and \u0026quot;Update roles for existing users\u0026quot; enabled, the CSV parser fails to correctly interpret the escape characters. This leads to cell merging, where the attacker's 'display_name' merges into the 'role' field and the 'nickname' rebalances the column count. Consequently, the user is assigned the 'administrator' role when the plugin processes the file.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated user with subscriber-level access to escalate their account to administrator status. This grants the attacker full control over the affected WordPress site, enabling malicious code execution, data exfiltration, or total site takeover. This vulnerability affects any WordPress instance utilizing the vulnerable plugin version and requires the administrator to perform an export/import maintenance task.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Import and export users and customers plugin to a version later than 2.4.17 immediately.\u003c/li\u003e\n\u003cli\u003eReview WordPress user role assignments for unexpected administrators, specifically those who were previously subscribers or customers.\u003c/li\u003e\n\u003cli\u003eDisable the plugin's \u0026quot;Update roles for existing users\u0026quot; feature if an update is not immediately feasible to prevent automatic role elevation during imports.\u003c/li\u003e\n\u003cli\u003eAudit recent CSV import logs for the Import and export users and customers plugin to identify potential exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-23T22:46:26Z","date_published":"2026-09-23T22:46:26Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-86583/","summary":"An escape character mismatch between CSV export and import functions in the Import and export users and customers WordPress plugin allows authenticated users to escalate privileges to administrator.","title":"Privilege Escalation in Import and export users and customers WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-86583/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wordpress:import_and_export_users_and_customers:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}