Executive brief
WP Import Export Lite is a WordPress plugin that allows administrators to manage content imports and exports. The plugin fails to properly escape custom field names when displaying them on administration screens, allowing users with basic contributor-level access to inject malicious scripts that will execute when administrators view the affected page. This enables attackers to steal admin credentials or perform unauthorized administrative actions.
Technical details
The vulnerability is a Stored Cross-Site Scripting (XSS) flaw (CWE-79) in the WP Import Export Lite plugin before version 3.9.33. The root cause is the failure to escape custom field names retrieved from the database before inserting them into the DOM of an administration screen. An attacker with contributor-level privileges can craft malicious field names containing JavaScript code and save them to the database. When an administrator visits the affected admin screen, the unescaped payload executes in their browser context, potentially allowing session hijacking or account compromise. The vulnerability has been fixed in version 3.9.33.
Affected products
- WP Import Export Lite WP Import Export Lite before 3.9.33
Timeline
- 2026-09-14: disclosed
- 2026-09-16: advisory
- 2026-09-16: patched: Fixed in version 3.9.33