rootpwn

high · CVSS v3 7.2 · EPSS 0.00132

CVE-2026-76554

The WP Import Export Lite plugin for WordPress contains a privilege escalation vulnerability due to insufficient permission checks during th

Overview

The WP Import Export Lite plugin for WordPress contains a privilege escalation vulnerability due to insufficient permission checks during the import process. Users with delegated access to the plugin can bypass standard WordPress role restrictions to create or modify user accounts, including administrators.

Description

The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to create or modify user accounts and assign roles, allowing users granted a delegated WP Import Export Lite WordPress plugin before 3.9.35 permission, who cannot otherwise manage users, to create administrator accounts and to overwrite the credentials and role of existing accounts, including administrators.

Impact

This vulnerability impacts Confidentiality, Integrity, and Availability by allowing unauthorized account creation and modification. It enables lower-privileged users with plugin access to elevate their permissions to administrator or overwrite existing admin credentials. This can lead to a complete compromise of the WordPress environment.

Remediation

Update the WP Import Export Lite plugin to version 3.9.35 or later. Administrators should also review user logs for unauthorized account modifications and ensure that plugin access is restricted to highly trusted personnel.

Risk context

The vulnerability is rated as High severity with a CVSS v3 score of 7.2. While the EPSS score is currently low at 0.00132, the risk of internal privilege escalation and site takeover makes this a high-priority patch for affected environments.

Affected products

  • WP Import Export Lite < 3.9.35

Scores

Severity
high
CVSS v2
8.3
CVSS v3
7.2
CVSS v4
EPSS
0.00132

WordPress Privilege Escalation Plugin Access Control CVE-2026-76554 Account Takeover

← All CVEs