CVE WATCH / VULNERABILITY DETAIL

CVE-2026-86583

HIGHCVSS 8.8NVD feed

Published 23 September 2026 · tracked since 24 September 2026

Description

The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. The vulnerability exists because the exporter writes CSV cells using fputcsv() with a NUL byte (\0) as

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-86583 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-86583

HIGHCVSS 8.8NVD feed

Published 23 September 2026 · tracked since 24 September 2026

Description

The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. The vulnerability exists because the exporter writes CSV cells using fputcsv() with a NUL byte (\0) as

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]