Sceawere
Vulnerability Detail
CVE-2026-104757UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Import and Export Users Privilege Escalation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 16h ago
- Vendor
- Javier Carazo
- Product
- Import and export users and customers
- Attack Type
- CWE-266 Incorrect Privilege Assignment
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Editor Privilege Escalation in Import and export users and customers <= 2.5.5 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-06T09:17:39.810Z",
"pubdate": "2026-10-06T09:17:39.810Z",
"executiveSummary": "The 'Import and export users and customers' plugin for WordPress is susceptible to an authorization bypass vulnerability.\nThis vulnerability is categorized as an improper access control issue, allowing an authenticated attacker with low-level privileges (such as an Editor or below) to elevate their privileges or perform administrative actions.\nThe flaw stems from insufficient validation of user capabilities during critical import or export operations.\nSuccessful exploitation grants an unauthorized user the ability to manipulate user data, modify account roles, or potentially achieve full administrative control over the WordPress instance.\nThe vulnerability affects versions 2.5.5 and below of the 'Import and export users and customers' plugin.\nGiven the nature of the plugin, which handles sensitive user databases, the risk to the confidentiality, integrity, and availability of the application is critical.\nAttackers do not require sophisticated infrastructure; they only need an active user account on the target system with access to the plugin's dashboard.\nThis vulnerability presents a significant risk to site security, enabling unauthorized actors to bypass established access control lists and compromise the user management subsystem.",
"technicalDetails": "The vulnerability resides within the access control logic of the 'Import and export users and customers' plugin, specifically in the mechanisms governing administrative plugin functions.\nThe root cause is an improper authorization check wherein the plugin fails to verify the current user's capabilities before executing sensitive functions. In many WordPress plugins, administrative actions should be protected by the 'manage_options' or equivalent high-level capability checks. The affected versions lack a restrictive permission guard, allowing users with lower-tier roles (such as Editor) to trigger functions intended exclusively for site administrators.\nThe attack flow begins with an authenticated attacker accessing the plugin's interface. Because the plugin does not properly validate the user's role against the required administrative threshold, the application processes the request despite the user's lack of elevated privileges.\nAn attacker can exploit this by manipulating the HTTP request parameters sent to the plugin's backend endpoints. By bypassing the restricted UI elements or sending direct POST requests to the vulnerable handlers, the attacker can invoke functions related to user imports or exports.\nSpecifically, the vulnerability allows an attacker to modify the user database. By injecting malicious user data or altering the roles of existing accounts during an import process, an attacker can promote their own account to 'Administrator'. The plugin essentially trusts the input provided through its import interface without re-verifying the caller's authorization context.\nFurthermore, the vulnerability permits the unauthorized export of sensitive customer or user data, which may contain personally identifiable information (PII), hashes, or metadata that could be used in secondary attacks.\nThe vulnerable component is the processing logic responsible for handling user data ingestion and management. Since the application fails to utilize the standard WordPress 'current_user_can()' function or similar nonce-based authorization tokens effectively, the application state remains vulnerable to unauthorized modification.\nPost-exploitation, an attacker gains complete control over the WordPress environment. They may install malicious plugins, execute arbitrary code via theme editing, or exfiltrate the entire user database. The persistence is near-guaranteed as the attacker can create new administrative accounts or modify existing ones to regain access if the initial session is terminated.\nThis vulnerability is effective across all deployments of the plugin versions 2.5.5 and earlier, assuming the attacker has an authenticated session within the WordPress administrative interface."
}