CVE-2026-76552: Unknown Wp Import Export Lite

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

The WP Import Export Lite WordPress plugin before 3.9.33 does not validate the type, extension or content of files it retrieves from a user-supplied URL during import, allowing users granted its import permission to store arbitrary files, including executable ones, on the server and achieve remote code execution.

Affected products

  • Unknown Wp Import Export Lite: before 3.9.33 (fixed in 3.9.33)

Published 2026-09-16. Last modified 2026-09-17.