Impact
The WP Import Export Lite WordPress plugin, versions earlier than 3.9.33, does not restrict the PHP functions that can be applied to exported field values. Users who possess export permission can supply field values that are interpreted as arbitrary PHP function names, causing those functions to execute on the server side. This flaw essentially permits any PHP code execution that the attacker can invoke, allowing them to compromise the confidentiality, integrity, and availability of the affected WordPress installation.
Affected Systems
All WordPress installations running the WP Import Export Lite plugin below version 3.9.33 are affected. The vulnerability is confined to the plugin code itself; no other WordPress core or third‑party components are impacted.
Risk and Exploitability
The EPSS score of less than 1% indicates that, according to current data, exploitation attempts are rare, and the vulnerability does not appear in the CISA KEV catalog, suggesting no known large‑scale attacks. However, the attack can only be launched by an authenticated user with export rights. Once authenticated, an attacker can craft a malicious value for an exported field that triggers an arbitrary PHP function, resulting in remote code execution. The CVSS score of 7.2 reflects the high severity of the flaw, but the overall risk is moderated by the low probability of exploitation.
OpenCVE Enrichment