VYPR

Wp Import Export Lite

by WordPress

CVEs (15)

  • CVE-2026-76552HigSep 16, 2026
    risk 0.57cvss 8.8epss 0.01

    The WP Import Export Lite WordPress plugin before 3.9.33 does not validate the type, extension or content of files it retrieves from a user-supplied URL during import, allowing users granted its import permission to store arbitrary files, including executable ones, on the server…

  • CVE-2025-6207HigAug 5, 2025
    risk 0.49cvss 7.5epss 0.01

    The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_tempalte_import' function in all versions up to, and including, 3.9.28. This makes it possible for authenticated attackers, with…

  • CVE-2025-5061HigAug 5, 2025
    risk 0.49cvss 7.5epss 0.01

    The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_parse_upload_data' function in all versions up to, and including, 3.9.29. This makes it possible for authenticated attackers, with…

  • CVE-2026-76554HigSep 19, 2026
    risk 0.47cvss 7.2epss 0.00

    The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to create or modify user accounts and assign roles, allowing users granted a delegated WP Import Export Lite WordPress plugin before 3.9.35 permission, who…

  • CVE-2026-76551HigSep 16, 2026
    risk 0.47cvss 7.2epss 0.01

    The WP Import Export Lite WordPress plugin before 3.9.33 does not restrict which PHP function may be applied to exported field values, allowing users granted its export permission to have arbitrary functions invoked on values they control, leading to remote code execution.

  • CVE-2026-76550HigSep 16, 2026
    risk 0.47cvss 7.2epss 0.01

    The WP Import Export Lite WordPress plugin before 3.9.34 does not validate a user-supplied output path when writing export files, allowing users granted its export permission to write files with arbitrary names to arbitrary locations on the server, leading to remote code…

  • CVE-2026-76558MedSep 16, 2026
    risk 0.44cvss 6.8epss 0.00

    The WP Import Export Lite WordPress plugin before 3.9.33 does not escape custom field names retrieved from the database before inserting them into the DOM of one of its administration screens, allowing users with a role as low as contributor to perform Stored XSS attacks which…

  • CVE-2026-76557MedSep 16, 2026
    risk 0.44cvss 6.8epss 0.00

    The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some import configuration values before using them in SQL statements, allowing users whose role an administrator has granted the WP Import Export Lite WordPress plugin before 3.9.33's…

  • CVE-2026-76556MedSep 16, 2026
    risk 0.44cvss 6.8epss 0.00

    The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some export filter values before using them in SQL statements, allowing users holding its export permission, which administrators have by default and may also grant to lower roles, to…

  • CVE-2026-76555MedSep 16, 2026
    risk 0.44cvss 6.8epss 0.00

    The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a user-supplied file path before reading it and copying it into a publicly accessible directory, allowing any user whose role an administrator has granted the WP Import Export Lite WordPress plugin before…

  • CVE-2026-76553MedSep 16, 2026
    risk 0.42cvss 6.5epss 0.00

    The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from stored, user-supplied data before recursively deleting the directory it resolves to, allowing users to whom an administrator has delegated a WP Import Export Lite WordPress plugin before…

  • CVE-2025-2839MedApr 22, 2025
    risk 0.35cvss 6.4epss 0.00

    The WP Import Export Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpiePreviewData’ function in all versions up to, and including, 3.9.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2024-31308MedApr 7, 2024
    risk 0.29cvss 4.4epss 0.00

    Deserialization of Untrusted Data vulnerability in VJInfotech WP Import Export Lite.This issue affects WP Import Export Lite: from n/a through 3.9.26.

  • CVE-2026-76559MedSep 16, 2026
    risk 0.27cvss 4.1epss 0.00

    The WP Import Export Lite WordPress plugin before 3.9.33 does not properly validate URLs before requesting them during the import process, allowing users with the import capability, which administrators hold by default, to make the site issue requests to internal hosts and…

  • CVE-2026-11397MedJul 3, 2026
    risk 0.00cvss 5.5epss 0.00

    The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and including 3.9.30 via the wpie_import_upload_file_from_url AJAX action. The plugin's URL downloader first calls wp_safe_remote_get() (which correctly blocks…