CVE-2026-76553: Unknown Wp Import Export Lite

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from stored, user-supplied data before recursively deleting the directory it resolves to, allowing users to whom an administrator has delegated a WP Import Export Lite WordPress plugin before 3.9.33 capability to delete arbitrary directories, and every file within them, including outside the web root.

Affected products

  • Unknown Wp Import Export Lite: before 3.9.33 (fixed in 3.9.33)

Published 2026-09-16. Last modified 2026-09-17.