Junglewise Threat Intelligence

CVE-2026-76555: WP Import Export Lite path traversal in file import

CVE-2026-76555 · Severity: medium · CVSS 6.8 · Published 2026-09-16

Vendors: Automattic.

Executive brief

The WP Import Export Lite WordPress plugin contains a file path validation flaw that allows administrators to grant import permissions to users who can then read sensitive files from anywhere on the server and copy them to publicly accessible directories. This vulnerability exposes confidential data such as configuration files, database credentials, and other server secrets to unauthorized disclosure.

Technical details

The vulnerability is a path traversal (CWE-22) in the file import functionality of WP Import Export Lite before version 3.9.33. The plugin fails to validate user-supplied file paths before reading and copying them to a publicly accessible directory, allowing authenticated users with import permission to access files outside the web root. Additionally, the vulnerable code path modifies file-system permissions on arbitrary paths regardless of whether the file copy succeeds. The attack requires that an administrator has granted the user the plugin's import permission. This is an authenticated vulnerability but can lead to disclosure of sensitive server-side information including configuration files and credentials.

Affected products

  • Automattic WP Import Export Lite before 3.9.33

Timeline

  • 2026-09-14: disclosed
  • 2026-09-16: patched: Fixed in version 3.9.33

References