Impact
The plugin fails to restrict which user meta keys can be updated via profile fields, allowing an attacker to set the wp_capabilities meta key and grant themselves Administrator privileges. This grants full control over the WordPress site, compromising confidentiality, integrity, and availability.
Affected Systems
WordPress sites using Import and export users and customers plugin version 1.29.7 or earlier, where the Show fields in profile setting is enabled and a CSV with a wp_capabilities column header has been previously imported, are affected.
Risk and Exploitability
The flaw carries a CVSS score of 8.1, indicating high severity. Exploitation requires that the target accepts CSV imports using the Show fields in profile setting and that an attacker submits a crafted registration request with wp_capabilities data. The vulnerability is not listed in the CISA KEV catalog and EPSS data is unavailable, yet the potential for granting full administrative control remains significant.
OpenCVE Enrichment