Description
The WP Import Export Lite WordPress plugin before 3.9.33 does not restrict which PHP function may be applied to exported field values, allowing users granted its export permission to have arbitrary functions invoked on values they control, leading to remote code execution.
Published: 2026-09-16
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The WP Import Export Lite WordPress plugin, versions earlier than 3.9.33, does not restrict the PHP functions that can be applied to exported field values. Users who possess export permission can supply field values that are interpreted as arbitrary PHP function names, causing those functions to execute on the server side. This flaw essentially permits any PHP code execution that the attacker can invoke, allowing them to compromise the confidentiality, integrity, and availability of the affected WordPress installation.

Affected Systems

All WordPress installations running the WP Import Export Lite plugin below version 3.9.33 are affected. The vulnerability is confined to the plugin code itself; no other WordPress core or third‑party components are impacted.

Risk and Exploitability

The EPSS score of less than 1% indicates that, according to current data, exploitation attempts are rare, and the vulnerability does not appear in the CISA KEV catalog, suggesting no known large‑scale attacks. However, the attack can only be launched by an authenticated user with export rights. Once authenticated, an attacker can craft a malicious value for an exported field that triggers an arbitrary PHP function, resulting in remote code execution. The CVSS score of 7.2 reflects the high severity of the flaw, but the overall risk is moderated by the low probability of exploitation.

Generated by OpenCVE AI on September 18, 2026 at 12:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the WP Import Export Lite plugin to version 3.9.33 or later.
  • Restrict the export permission to trusted administrators or remove export capability for non‑admin roles.
  • If an upgrade is not yet possible, disable the export feature in the plugin settings or delete the plugin until a patch is available.

Generated by OpenCVE AI on September 18, 2026 at 12:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Wed, 16 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Import Export Lite WordPress plugin before 3.9.33 does not restrict which PHP function may be applied to exported field values, allowing users granted its export permission to have arbitrary functions invoked on values they control, leading to remote code execution.
Title WP Import Export Lite < 3.9.33 - Authenticated RCE via Export Field PHP Function
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-17T12:41:28.188Z

Reserved: 2026-08-19T12:52:32.418Z

Link: CVE-2026-76551

cve-icon Vulnrichment

Updated: 2026-09-17T12:22:44.023Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T06:16:31.987

Modified: 2026-09-17T13:16:45.787

Link: CVE-2026-76551

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T12:30:08Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')