Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-86583— Import and export users and customers <= 2.4.17 - Authenticated (Subscriber+) Privilege Escalation via CSV Escape-Character Mismatch in Export/Import Round Trip via display_name and nickname Profile Fields

Quick assessment

Affected
carazo Import and export users and customers
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 的 Import and Export Users and Customers 插件在所有 2.4.17 及以下版本中存在权限提升漏洞,该漏洞可通过插件自身的导出和重新导入流程触发。漏洞原因是:导出模块在使用 写入 CSV 单元格时,将空字节( )作为转义字符;而导入模块在解析同一文件时,使用 且仅传入分隔符参数,未指定转义字符,导致 PHP 默认使用反斜杠( )作为转义字符。 由于导出列布局中,“显示名称”(display_name)字段紧邻“角色”(role)字段之前,而“昵称”(nickn

CVSS 8.8 · High EPSS 0.33% · P24
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-86583

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Import and export users and customers <= 2.4.17 - Authenticated (Subscriber+) Privilege Escalation via CSV Escape-Character Mismatch in Export/Import Round Trip via display_name and nickname Profile Fields
Source: CVE Program / CVE List V5
Vulnerability Description
The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. The vulnerability exists because the exporter writes CSV cells using fputcsv() with a NUL byte (\0) as the escape character, while the importer parses the same file using SplFileObject::fgetcsv() with only a single delimiter argument, causing PHP's default backslash escape character to be applied instead; because the export column layout places display_name immediately before the role column and nickname immediately after, an attacker can store crafted values in those two profile fields — saved by WordPress core via the standard profile page — such that the escape mismatch causes the parser to merge the display_name cell into the role field and rebalance the column count via nickname, yielding administrator as the parsed role for their own row when it reaches the import_user function's add_role function. This makes it possible for authenticated attackers with Subscriber-level access or above to escalate their privileges to Administrator. Exploitation requires a site administrator to trigger the plugin's documented export re-import migration with both "Update existing users" and "Update roles for existing users" set to "yes".
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
特权授予不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
carazo Import and export users and customers 0 ~ 2.4.17 -

II. Public POCs for CVE-2026-86583

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-86583

请登录查看更多情报信息。

News Coverage for CVE-2026-86583 (1)

Other References for CVE-2026-86583 (6)

IV. Related Vulnerabilities

V. Comments for CVE-2026-86583

No comments yet


Leave a comment