CVE-2026-86583 - Import and export users and customers = 2.4.17 - Authenticated (Subscriber+) Privilege Escalation via CSV Escape-Character Mismatch in Export/Import Round Trip via display_name and nickname Profile
Brief
CVE ID : CVE-2026-86583
Published : Sept. 23, 2026, 10:16 p. m.
- 42 minutes ago
Description : The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.
- 17 via the plugin's own export and re-import workflow.
