Sceawere

Vulnerability Detail

CVE-2026-104757UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Import and Export Users Privilege Escalation

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
16h ago
Vendor
Javier Carazo
Product
Import and export users and customers
Attack Type
CWE-266 Incorrect Privilege Assignment
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Editor Privilege Escalation in Import and export users and customers <= 2.5.5 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-06T09:17:39.810Z",
  "pubdate": "2026-10-06T09:17:39.810Z",
  "executiveSummary": "The 'Import and export users and customers' plugin for WordPress is susceptible to an authorization bypass vulnerability.\nThis vulnerability is categorized as an improper access control issue, allowing an authenticated attacker with low-level privileges (such as an Editor or below) to elevate their privileges or perform administrative actions.\nThe flaw stems from insufficient validation of user capabilities during critical import or export operations.\nSuccessful exploitation grants an unauthorized user the ability to manipulate user data, modify account roles, or potentially achieve full administrative control over the WordPress instance.\nThe vulnerability affects versions 2.5.5 and below of the 'Import and export users and customers' plugin.\nGiven the nature of the plugin, which handles sensitive user databases, the risk to the confidentiality, integrity, and availability of the application is critical.\nAttackers do not require sophisticated infrastructure; they only need an active user account on the target system with access to the plugin's dashboard.\nThis vulnerability presents a significant risk to site security, enabling unauthorized actors to bypass established access control lists and compromise the user management subsystem.",
  "technicalDetails": "The vulnerability resides within the access control logic of the 'Import and export users and customers' plugin, specifically in the mechanisms governing administrative plugin functions.\nThe root cause is an improper authorization check wherein the plugin fails to verify the current user's capabilities before executing sensitive functions. In many WordPress plugins, administrative actions should be protected by the 'manage_options' or equivalent high-level capability checks. The affected versions lack a restrictive permission guard, allowing users with lower-tier roles (such as Editor) to trigger functions intended exclusively for site administrators.\nThe attack flow begins with an authenticated attacker accessing the plugin's interface. Because the plugin does not properly validate the user's role against the required administrative threshold, the application processes the request despite the user's lack of elevated privileges.\nAn attacker can exploit this by manipulating the HTTP request parameters sent to the plugin's backend endpoints. By bypassing the restricted UI elements or sending direct POST requests to the vulnerable handlers, the attacker can invoke functions related to user imports or exports.\nSpecifically, the vulnerability allows an attacker to modify the user database. By injecting malicious user data or altering the roles of existing accounts during an import process, an attacker can promote their own account to 'Administrator'. The plugin essentially trusts the input provided through its import interface without re-verifying the caller's authorization context.\nFurthermore, the vulnerability permits the unauthorized export of sensitive customer or user data, which may contain personally identifiable information (PII), hashes, or metadata that could be used in secondary attacks.\nThe vulnerable component is the processing logic responsible for handling user data ingestion and management. Since the application fails to utilize the standard WordPress 'current_user_can()' function or similar nonce-based authorization tokens effectively, the application state remains vulnerable to unauthorized modification.\nPost-exploitation, an attacker gains complete control over the WordPress environment. They may install malicious plugins, execute arbitrary code via theme editing, or exfiltrate the entire user database. The persistence is near-guaranteed as the attacker can create new administrative accounts or modify existing ones to regain access if the initial session is terminated.\nThis vulnerability is effective across all deployments of the plugin versions 2.5.5 and earlier, assuming the attacker has an authenticated session within the WordPress administrative interface."
}
CVE-2026-104757: Import and Export Users Privilege Escalation (HIGH Severity, CVSS: 7.2) | Sceawere