WordPress 插件 “Import and export users and customers” 在 2.5.2 之前版本中,在通过 CSV 文件导入并分配角色时,未正确执行 权限要求,导致仅拥有 权限的用户能够创建新的管理员账户,或把现有用户提升为管理员。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Import and export users and customers | 2.4.16 ~ 2.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84223 | Kirki 6.0.0 - 6.3.0 - Author+ Stored XSS via Unsanitized SVG Upload | |
| CVE-2026-14844 | Master Slider <= 3.11.2 - Contributor+ Stored XSS via ms_slider Shortcode Attributes | |
| CVE-2026-16542 | Import and export users and customers < 2.4.5 - Admin+ SSRF via bp_avatar | |
| CVE-2026-81650 | NextGEN Gallery < 4.5.0 - Authenticated Arbitrary File Upload via ZIP Import | |
| CVE-2026-81652 | NextGEN Gallery < 4.5.0 - Contributor+ Image Metadata Disclosure via IDOR | |
| CVE-2026-81653 | NextGEN Gallery < 4.5.0 - Authenticated Arbitrary Gallery Image Deletion via IDOR | |
| CVE-2026-81654 | NextGEN Gallery < 4.5.0 - Authenticated Plugin Image Settings Update | |
| CVE-2026-81651 | NextGEN Gallery < 4.5.0 - Authenticated Cross-Gallery Settings Modification via IDOR | |
| CVE-2026-87068 | Forminator Forms < 1.57.2.1 - Authenticated Privilege Escalation via Quiz Lead-Form Import | |
| CVE-2026-87067 | Forminator Forms < 1.57.2.1 - Authenticated RCE via XML-RPC PHP Object Injection | |
| CVE-2026-92541 | Import and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Admini | |
| CVE-2026-85017 | Unlimited Elements For Elementor < 2.0.20 - Subscriber+ PHP Object Injection | |
| CVE-2026-82842 | SAML Single Sign On < 6.0.0 - Unauthenticated Privilege Escalation via Account Matching | |
| CVE-2026-87840 | Tripzzy < 1.5.1 - Unauthenticated Booking Data Tampering | |
| CVE-2026-87839 | Tripzzy < 1.5.1 - Unauthenticated Arbitrary Comment Deletion | |
| CVE-2026-92410 | Sign-up Sheets < 2.4.0 - Arbitrary Sign-up Deletion via CSRF | |
| CVE-2026-92423 | Meow Gallery < 5.5.5 - Author+ Draft and Private Post Disclosure via fetch_posts | |
| CVE-2026-92422 | Meow Gallery < 5.5.5 - Unauthenticated Arbitrary Shortcode Execution via load_gallery_coll | |
| CVE-2026-92965 | TikTok 1.2.0 - 1.4.1 - Unauthenticated OAuth Code Redemption |
No comments yet