CVE-2026-7641Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 2.0.8 via the `save_extra_user_profile_fields()` function. This is due to an incomplete blocklist that correctly restricts capability meta keys for the primary site (e.g., `wp_capabilities`, `wp_user_level`) but fails to block the equivalent meta keys for any other subsite in a WordPress Multisite network (e.g., `wp_2_capabilities`, `wp_2_user_level`), allowing these keys to pass the `in_array()` check and be written directly to user meta via `update_user_meta()`. This makes it possible for authenticated attackers, with Subscriber-level access and above, to escalate their privileges to Administrator on any subsite within the Multisite network by submitting a crafted profile update to `/wp-admin/profile.php`. Exploitation requires that an administrator has previously imported a CSV file containing multisite-prefixed capability column headers and has enabled the 'Show fields in profile?' option, which causes those keys to be stored in the `acui_columns` option and exposed as editable fields on the user profile page.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-02); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-02: 2Mentions · 2026-05-14: 1Patch / Workaround · 2026-05-14: 1Technical Details · 2026-05-02: 2Technical Details · 2026-05-14: 105-0205-14
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-022
Disclosure1General1
2026-05-141
Patch1
Full discourse3 posts
  • ADK Cyber@ADKCyber
    Patch

    A new high-severity WordPress multisite vulnerability (CVE-2026-7641) allows privilege escalation via user profile updates if certain plugin settings are enabled. Mohawk Valley SMBs using multisite should review and update Import and export users plugin ASAP. #Cybersecurity

    Post summary

    The post reports a high‑severity privilege‑escalation flaw in WordPress multisite, tied to plugin settings, and urges users to update the relevant plugin immediately.

    0000046
    80 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-7641 Privilege Escalation in Import and Export Users Customers ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7641 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The message announces CVE-2026-7641 as a privilege escalation issue involving import/export users, but it offers no proof of concept, exploit code, active usage, patch, or detailed technical analysis beyond the basic vulnerability type.

    0000057
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-7641 The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up… CVSS 8.8 Full analysis → https://sec.kaitan.id/cves/CVE-2026-7641 #WordPress #CyberSecurity #InfoSec

    Post summary

    A high‑severity CVE (CVE‑2026‑7641) affecting the WordPress Import and export users and customers plugin is disclosed, with the vulnerability type and CVSS score provided and a link to a full analysis, but no PoC, active exploitation, or patch info is included.

    0000046
    458 followersView on X

Explore more