Impact
The WP Import Export Lite WordPress plugin before version 3.9.33 fails to validate the type, extension, or content of files retrieved from a user‑supplied URL during import. This flaw lets any user with import permission upload arbitrary files—including executable scripts—to the server. If an attacker uploads a malicious script such as a PHP web shell, they can run arbitrary code on the host, effectively taking full control of the site.
Affected Systems
WordPress sites running the WP Import Export Lite plugin at any release prior to 3.9.33 are affected. The plugin is distributed under an unknown vendor, but any installation of the plugin in these versions is vulnerable.
Risk and Exploitability
The vulnerability requires authenticated access with permission to use the import feature; the caller supplies a remote URL pointing to a malicious file. The EPSS score shows less than 1% probability of exploitation, so real‑world activity appears low, yet the impact is catastrophic due to the remote code execution potential. The plugin is not listed in the CISA KEV catalog, but the lack of a patch and the high severity of the flaw warrant immediate remediation.
OpenCVE Enrichment