CVE-2026-3629Disclosure

LOWCVSS 8.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' function not properly restricting which user meta keys can be updated via profile fields. The 'get_restricted_fields' method does not include sensitive meta keys such as 'wp_capabilities'. This makes it possible for unauthenticated attackers to escalate their privileges to Administrator by submitting a crafted registration request that sets the 'wp_capabilities' meta key. The vulnerability can only be exploited if the "Show fields in profile" setting is enabled and a CSV with a wp_capabilities column header has been previously imported.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-21); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-03-21: 2Mentions · 2026-03-22: 2Mentions · 2026-05-19: 1PoC Mentioned / Linked · 2026-05-19: 1Technical Details · 2026-03-21: 2Technical Details · 2026-03-22: 103-2103-2205-19
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-212
Disclosure2
2026-03-222
Disclosure2
2026-05-191
General1
Full discourse5 posts
  • Clandestine@akaclandestine
    General

    GitHub - PySecTools/CVE-2026-3629: WordPress Privilege Escalation Checker · GitHub https://github.com/PySecTools/CVE-2026-3629

    Post summary

    The text lists a GitHub repository related to CVE‑2026‑3629, likely containing a checker tool, but provides no evidence of an exploit, patch, or active exploitation.

    024081475.2K
    62.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3629 The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 's… https://www.cve.org/CVERecord?id=CVE-2026-3629

    Post summary

    The Import and Export Users and Customers WordPress plugin is vulnerable to privilege escalation in versions up to 1.29.7, as identified by CVE-2026-3629.

    0000058
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-3629 - carazo - Import and export users and customers - https://www.redpacketsecurity.com/cve-alert-cve-2026-3629-carazo-import-and-export-users-and-customers/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-3629 #carazo #import-and-export-users-and-customers

    Post summary

    The post announces the discovery of CVE-2026-3629 (codenamed carazo) and directs readers to a Red Packet Security article for more information.

    0000067
    3.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3629 WordPress Import/Export Users Plugin Privilege Escalation via Unauthorized Meta Key Modification https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3629

    Post summary

    The text announces a newly disclosed WordPress plugin privilege‑escalation vulnerability, but provides only high‑level details without PoC, exploit, or mitigation information.

    0000026
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-3629 - High The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_f... https://www.thehackerwire.com/vulnerability/CVE-2026-3629/ https://t.co/X9vei6108d

    Post summary

    The WordPress Import and Export Users and Customers plugin is vulnerable to privilege escalation up to version 1.29.7, with technical details provided but no PoC, exploit, or patch mentioned.

    0000025
    138 followersView on X

Explore more