Sceawere

Vulnerability Detail

CVE-2026-94178UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Subscriber Privilege Escalation in Import and Export Users and Customers

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
Javier Carazo
Product
Import and export users and customers
Attack Type
CWE-266 Incorrect Privilege Assignment
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Subscriber Privilege Escalation in Import and export users and customers <= 2.5.2 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-30T13:17:25.953Z",
  "pubdate": "2026-09-30T13:17:25.953Z",
  "executiveSummary": "The 'Import and export users and customers' plugin for WordPress, specifically versions 2.5.2 and below, is susceptible to a privilege escalation vulnerability.\nThis security flaw stems from improper access control validation during the user import or update process, allowing authenticated users with low-level privileges (subscribers) to manipulate their own account permissions or escalate privileges to administrative levels.\nThe vulnerability represents a critical risk as it enables unauthorized users to achieve full administrative control over the affected WordPress instance.\nSuccessful exploitation requires the attacker to have an active subscriber account on the target system.\nBy submitting a specially crafted request during the user management flow, an attacker can bypass authorization checks, potentially resulting in complete system compromise, data theft, or arbitrary code execution if combined with other administrative-level features.",
  "technicalDetails": "The vulnerability resides within the functional logic responsible for handling user data importation and profile updates. In versions 2.5.2 and earlier, the plugin fails to implement server-side verification of the user's current roles and capabilities before processing user meta or role-based parameters supplied via HTTP requests.\nThe root cause is an insecure implementation of user role assignment. When the plugin processes incoming user data, it trusts the role information provided in the request payload without re-validating the initiator's authority to modify such parameters. This allows an authenticated subscriber to inject or overwrite their 'wp_capabilities' or 'user_level' metadata during the interaction with the plugin's import or update functions.\nThe attack flow proceeds as follows: First, an attacker authenticates as a standard subscriber. Second, the attacker interacts with the plugin’s interface, typically by triggering an import action or a user profile update request that is routed through the plugin's vulnerable processing functions. Third, the attacker modifies the request, inserting or altering the role metadata field to include the 'administrator' role. Fourth, because the plugin lacks an explicit capability check (e.g., current_user_can('manage_options')) during this write operation, the WordPress database is updated to assign the elevated role to the attacker's account.\nThe exploitation does not require advanced network conditions; it is performed directly through the application's interface via HTTP POST requests. Because the vulnerability lies within the plugin's internal handling of user input, it bypasses standard WordPress hardening techniques that usually prevent subscriber-level accounts from modifying their own roles.\nThe post-exploitation impact is severe. Upon successfully changing their role to administrator, the attacker gains unrestricted access to the WordPress administrative dashboard. This provides the capability to install arbitrary plugins or themes, modify database content, access sensitive user data, and execute arbitrary code on the server, effectively granting full control over the site's environment and the underlying hosting infrastructure."
}
CVE-2026-94178: Subscriber Privilege Escalation in Import and Export Users and Customers (HIGH Severity, CVSS: 7.5) | Sceawere