Import and export users and customers <= 2.4.17 - Authenticated (Subscriber+) Privilege Escalation via CSV Escape-Character Mismatch in Export/Import Round Trip via display_name and nickname Profile Fields
Strategic Overview
- Status
- Patched in 2.4.18
- Affected Plugin
- Import and export users and customers
- Affected Version
<= 2.4.17- CVSS
- 8.8High
- Weakness type
- CWE-266 · Incorrect Privilege Assignment
- CVE
CVE-2026-86583
At a glance
CVE-2026-86583 is a high-severity Incorrect Privilege Assignment vulnerability in the Import and export users and customers WordPress plugin, affecting versions <= 2.4.17. It carries a CVSS score of 8.8 (reachable over the network; low attack complexity; high confidentiality, integrity, availability impact). Exploitation requires an authenticated account at Subscriber level or above. The issue is fixed in version 2.4.18; sites on affected versions should update now. Disclosed September 2026, reported by khanhnv.
Vulnerability Overview
The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. The vulnerability exists because the exporter writes CSV cells using fputcsv() with a NUL byte (\0) as the escape character, while the importer parses the same file using SplFileObject::fgetcsv() with only a single delimiter argument, causing PHP's default backslash escape character to be applied instead; because the export column layout places display_name immediately before the role column and nickname immediately after, an attacker can store crafted values in those two profile fields — saved by WordPress core via the standard profile page — such that the escape mismatch causes the parser to merge the display_name cell into the role field and rebalance the column count via nickname, yielding administrator as the parsed role for their own row when it reaches the import_user function's add_role function. This makes it possible for authenticated attackers with Subscriber-level access or above to escalate their privileges to Administrator. Exploitation requires a site administrator to trigger the plugin's documented export re-import migration with both "Update existing users" and "Update roles for existing users" set to "yes".
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no interaction from a victim user. A successful exploit has high impact on confidentiality, integrity, availability — full site compromise territory.
CWE-266: Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Remediation
Update to version 2.4.18, or a newer patched version
How does WordSec protect against this?
Because it turns on account access, WordSec's login security is the relevant layer: role-based two-factor, captcha and brute-force limits raise the cost of getting the account this needs. None of that substitutes for the fix: Import and export users and customers 2.4.18 closes this, and updating the plugin is the step that ends it.
- Login Security
- Alerts
External References
Related records
Other vulnerabilities in Import and export users and customers
- 8.8CVE-2026-7641: Import and export users… Privilege Escalation
CVE-2026-7641 - 8.8CVE-2019-15329: Import and export users and customers <= 1.14.0.2 CSRF
CVE-2019-15329 - 8.1CVE-2026-3629: Import and export users… Privilege Escalation
CVE-2026-3629 - 8.0CVE-2022-3558: Import and export users and customers CSV Injection
CVE-2022-3558 - 7.7Import and export users and customers 1.15 Sensitive Data Exposure
- 7.5CVE-2019-15326: Import and export users… Directory Traversal
CVE-2019-15326 - 7.3CVE-2020-22277: Import and export users and customers CSV injection
CVE-2020-22277 - 7.2CVE-2026-92540: Import and export users… Privilege Escalation
CVE-2026-92540
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C