Junglewise Threat Intelligence

CVE-2026-76554: WP Import Export Lite privilege escalation in user import

CVE-2026-76554 · Severity: high · CVSS 7.2 · Published 2026-09-19

Executive brief

WP Import Export Lite is a WordPress plugin that allows users to import and export data, including user accounts. The plugin fails to properly verify permissions during user imports, allowing users with limited plugin access to create new administrator accounts or take over existing ones, including those of real administrators. An attacker with plugin permissions but no user management rights can escalate themselves to full site control.

Technical details

An authenticated privilege escalation in WP Import Export Lite before 3.9.35 occurs due to insufficient authorization checks in the user import functionality. Users granted delegated plugin permissions can bypass role restrictions to create admin accounts and modify existing user credentials and roles. The vulnerability requires authentication and plugin delegation but allows an attacker to circumvent the normal WordPress user management capabilities.

Affected products

  • WP Import Export Lite WP Import Export Lite before 3.9.35

Timeline

  • 2026-09-17: disclosed
  • 2026-09-19: patched: Fixed in version 3.9.35

References