目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-86583— Import and export users and customers <= 2.4.17 权限提升漏洞

一分钟漏洞结论

影响对象
carazo Import and export users and customers
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

WordPress 的 Import and Export Users and Customers 插件在所有 2.4.17 及以下版本中存在权限提升漏洞,该漏洞可通过插件自身的导出和重新导入流程触发。漏洞原因是:导出模块在使用 写入 CSV 单元格时,将空字节( )作为转义字符;而导入模块在解析同一文件时,使用 且仅传入分隔符参数,未指定转义字符,导致 PHP 默认使用反斜杠( )作为转义字符。 由于导出列布局中,“显示名称”(display_name)字段紧邻“角色”(role)字段之前,而“昵称”(nickn

CVSS 8.8 · High EPSS 0.33% · P24
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-86583 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Import and export users and customers <= 2.4.17 - Authenticated (Subscriber+) Privilege Escalation via CSV Escape-Character Mismatch in Export/Import Round Trip via display_name and nickname Profile Fields
来源: CVE Program / CVE List V5
Vulnerability Description
The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. The vulnerability exists because the exporter writes CSV cells using fputcsv() with a NUL byte (\0) as the escape character, while the importer parses the same file using SplFileObject::fgetcsv() with only a single delimiter argument, causing PHP's default backslash escape character to be applied instead; because the export column layout places display_name immediately before the role column and nickname immediately after, an attacker can store crafted values in those two profile fields — saved by WordPress core via the standard profile page — such that the escape mismatch causes the parser to merge the display_name cell into the role field and rebalance the column count via nickname, yielding administrator as the parsed role for their own row when it reaches the import_user function's add_role function. This makes it possible for authenticated attackers with Subscriber-level access or above to escalate their privileges to Administrator. Exploitation requires a site administrator to trigger the plugin's documented export re-import migration with both "Update existing users" and "Update roles for existing users" set to "yes".
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
特权授予不正确
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
carazo Import and export users and customers 0 ~ 2.4.17 -

二、漏洞 CVE-2026-86583 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-86583 的情报信息

请登录查看更多情报信息。

CVE-2026-86583 新闻报道 (1)

CVE-2026-86583 其他参考 (6)

IV. Related Vulnerabilities

V. Comments for CVE-2026-86583

暂无评论


发表评论