Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
internet-facing-service-vulnerabilityidentity-authentication-vulnerabilityinitial-access-method

WordPress Plugin Flaws Enable Privilege Escalation to Administrator

Updated 3mo agoFirst seen Mar 21, 20262 sources

Two newly disclosed vulnerabilities in WordPress plugins can let attackers elevate privileges to Administrator by abusing improper handling of user profile metadata. CVE-2026-4261 affects Expire Users through version 1.2.2, where the save_extra_user_profile_fields function allows modification of the on_expire_default_to_role meta value; an authenticated attacker with Subscriber-level access or higher can exploit the flaw to gain full administrative control. The issue was classified as CWE-862 and carries a high-severity CVSS v3.1 score with the vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.

A second flaw, CVE-2026-3629, impacts Import and export users and customers through version 1.29.7 and can, under specific conditions, allow even unauthenticated attackers to become administrators. The plugin's save_extra_user_profile_fields logic fails to block sensitive keys such as wp_capabilities because get_restricted_fields does not restrict them, enabling a crafted registration request to assign elevated privileges when "Show fields in profile" is enabled and a previously imported CSV included a wp_capabilities column header. That vulnerability was classified as CWE-269 with a CVSS v3.1 vector of AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H.

Share:
WordPress Plugin Flaws Enable Privilege Escalation to Administrator
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Mar 21, 20263mo ago

CVE-2026-3629 disclosed for Import and export users and customers

A privilege-escalation vulnerability affecting Import and export users and customers versions up to 1.29.7 was disclosed. Under specific conditions, an unauthenticated attacker can submit a crafted registration request to set wp_capabilities and obtain administrator privileges.

CVE-2026-4261 disclosed for Expire Users plugin

A privilege-escalation vulnerability affecting Expire Users versions up to 1.2.2 was disclosed. The flaw allows an authenticated Subscriber-level user or higher to modify the on_expire_default_to_role meta via save_extra_user_profile_fields and gain administrator privileges.

Wordfence receives reports for CVE-2026-4261 and CVE-2026-3629

Wordfence received vulnerability reports on March 21, 2026 for two WordPress plugin privilege-escalation flaws: CVE-2026-4261 in Expire Users and CVE-2026-3629 in Import and export users and customers.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

4 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.