What is CVE-2026-16534?
The 'Import and export users and customers' WordPress plugin before version 2.4.2 fails to enforce role-assignment and per-user edit permissions during CSV import, enabling a user with only user-creation capability to create an administrator account or overwrite an existing one. Site owners should update the plugin to at least version 2.4.2.
Azərbaycanca: 'Import and export users and customers' WordPress plaginində (2.4.2-dən əvvəlki versiyalar) CSV idxalı zamanı rol təyinatı və redaktə icazələri düzgün tətbiq edilmədiyi üçün, yalnız istifadəçi yaratma səlahiyyəti olan şəxs administrator hesabı yarada və ya mövcud administratoru üzərinə yaza bilər. Sayt sahibləri plaqini ən azı 2.4.2 versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which versions of the 'Import and export users and customers' plugin are affected by CVE-2026-16534?
This vulnerability affects versions of the plugin before 2.4.2.
Can an authenticated user exploiting CVE-2026-16534 create an administrator account?
Yes. A user with only user-creation capability can create an administrator account due to improperly enforced role-assignment during CSV import.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.