Junglewise Threat Intelligence

CVE-2026-76552: WP Import Export Lite arbitrary file upload via remote import

CVE-2026-76552 · Severity: high · CVSS 8.8 · Published 2026-09-16

Vendors: Meow Apps.

Executive brief

WP Import Export Lite is a WordPress plugin that allows site administrators to import data from external sources. The plugin fails to properly validate files downloaded from user-supplied URLs during import operations, allowing attackers with import permissions to upload malicious executable files to the web server and execute arbitrary code.

Technical details

The vulnerability is an arbitrary file upload flaw in the WP Import Export Lite plugin versions before 3.9.33. The plugin's remote file import functionality does not validate the file type, extension, or content of files retrieved from user-controlled URLs, allowing attackers with import permissions to upload arbitrary files, including executable PHP scripts. The attack requires the attacker to have import permissions on the WordPress site (typically an authenticated user with contributor or higher privileges). A successful exploit allows remote code execution with the privileges of the web server process. The vulnerability was fixed in version 3.9.33.

Affected products

  • Meow Apps WP Import Export Lite before 3.9.33

Timeline

  • 2026-09-14: disclosed
  • 2026-09-16: patched: Fixed in version 3.9.33

References