CVE-2026-76553: Unknown Wp Import Export Lite
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from stored, user-supplied data before recursively deleting the directory it resolves to, allowing users to whom an administrator has delegated a WP Import Export Lite WordPress plugin before 3.9.33 capability to delete arbitrary directories, and every file within them, including outside the web root.
Affected products
- Unknown Wp Import Export Lite: before 3.9.33 (fixed in 3.9.33)
Published 2026-09-16. Last modified 2026-09-17.