high · CVSS v3 7.2 · EPSS 0.00132
CVE-2026-76554
The WP Import Export Lite plugin for WordPress contains a privilege escalation vulnerability due to insufficient permission checks during th
Overview
The WP Import Export Lite plugin for WordPress contains a privilege escalation vulnerability due to insufficient permission checks during the import process. Users with delegated access to the plugin can bypass standard WordPress role restrictions to create or modify user accounts, including administrators.
Description
The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to create or modify user accounts and assign roles, allowing users granted a delegated WP Import Export Lite WordPress plugin before 3.9.35 permission, who cannot otherwise manage users, to create administrator accounts and to overwrite the credentials and role of existing accounts, including administrators.
Impact
This vulnerability impacts Confidentiality, Integrity, and Availability by allowing unauthorized account creation and modification. It enables lower-privileged users with plugin access to elevate their permissions to administrator or overwrite existing admin credentials. This can lead to a complete compromise of the WordPress environment.
Remediation
Update the WP Import Export Lite plugin to version 3.9.35 or later. Administrators should also review user logs for unauthorized account modifications and ensure that plugin access is restricted to highly trusted personnel.
Risk context
The vulnerability is rated as High severity with a CVSS v3 score of 7.2. While the EPSS score is currently low at 0.00132, the risk of internal privilege escalation and site takeover makes this a high-priority patch for affected environments.
Affected products
- WP Import Export Lite < 3.9.35
Scores
- Severity
- high
- CVSS v2
- 8.3
- CVSS v3
- 7.2
- CVSS v4
- —
- EPSS
- 0.00132