- Objective
- Test the hypothesis that role restrictions during user import can be bypassed through wp_capabilities metadata
- Path
- A missing authorization check (CWE-862) in the import handler: the plugin never verified who may assign arbitrary roles. A CSV of user_login,user_email,user_pass,role,wp_capabilities — with role=administrator or the serialized a:1:{s:13:"administrator";b:1;} — created full administrators from a low-privileged (low-importer) account. Logging in under the created account meant complete control of the site: plugins, themes, code execution.
- Detected
- Exploitation leaves almost no trace: creating users looks like the plugin's normal job. Watch for administrators created outside the admin UI and for import entries in audit logs
After: The 0-day was reported to the vendor; the write-up and PoC are public (codeby.net, Sep 28, 2026). Until a patch: never grant create_users outside the administrators, disable the plugin, monitor newly created admins.