Wp Import Export Lite

WordPress plugin · wp-import-export-lite · WordPress.org ↗
0
Critical
4
High
10
Known total
0
Unfixed
Running Wp Import Export Lite on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
HIGH
CVSS 7.2
WP Import Export Lite < 3.9.35 - Authenticated Privilege Escalation via User Import
CVE.org
>=0, <3.9.35 v3.9.35 CVE-2026-76554 Sep 19, 2026
HIGH
CVSS 7.2
WP Import Export Lite < 3.9.34 - Authenticated RCE via Export Template Path Traversal
CVE.org
>=0, <3.9.34 v3.9.34 CVE-2026-76550 Sep 16, 2026
HIGH
CVSS 7.2
WP Import Export Lite < 3.9.33 - Authenticated RCE via Export Field PHP Function
CVE.org
>=0, <3.9.33 v3.9.33 CVE-2026-76551 Sep 16, 2026
HIGH
CVSS 8.8
WP Import Export Lite < 3.9.33 - Authenticated Arbitrary File Upload via Remote Image Import
CVE.org
>=0, <3.9.33 v3.9.33 CVE-2026-76552 Sep 16, 2026
MEDIUM
CVSS 6.8
WP Import Export Lite < 3.9.33 - Authenticated Sensitive File Disclosure via Existing File Import Path Traversal
CVE.org
>=0, <3.9.33 v3.9.33 CVE-2026-76555 Sep 16, 2026
MEDIUM
CVSS 6.8
WP Import Export Lite < 3.9.33 - Authenticated SQLi via Export Filter Rules
CVE.org
>=0, <3.9.33 v3.9.33 CVE-2026-76556 Sep 16, 2026
MEDIUM
CVSS 6.8
WP Import Export Lite < 3.9.33 - Authenticated SQLi via Import Options
CVE.org
>=0, <3.9.33 v3.9.33 CVE-2026-76557 Sep 16, 2026
MEDIUM
CVSS 6.8
WP Import Export Lite < 3.9.33 - Contributor+ Stored DOM XSS via Custom Field Names
CVE.org
>=0, <3.9.33 v3.9.33 CVE-2026-76558 Sep 16, 2026
MEDIUM
CVSS 4.1
WP Import Export Lite < 3.9.33 - Admin+ SSRF via Import URL Handling
CVE.org
>=0, <3.9.33 v3.9.33 CVE-2026-76559 Sep 16, 2026
MEDIUM
CVSS 6.5
WP Import Export Lite < 3.9.33 - Authenticated Arbitrary Directory Deletion via Template Path Traversal
CVE.org
>=0, <3.9.33 v3.9.33 CVE-2026-76553 Sep 16, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.