Impact
The WP Import Export Lite WordPress plugin before version 3.9.33 fails to validate the type, extension or content of files it retrieves from a user‑supplied URL during import. This flaw allows any user with import permission to upload arbitrary files, including executable scripts, onto the server. If an attacker obtains a malicious script such as a PHP web shell, they can run arbitrary code on the host, effectively gaining full control of the site.
Affected Systems
WordPress sites running the WP Import Export Lite plugin at any release prior to 3.9.33 are vulnerable. The plugin is distributed under an unknown vendor, but any installation of the plugin in these versions is susceptible to exploitation.
Risk and Exploitability
The vulnerability requires authenticated access with permission to use the import feature; the attacker supplies a remote URL pointing to a malicious file. The EPSS score indicates less than 1% probability of exploitation, suggesting low real‑world activity. However, the impact is catastrophic due to the potential for remote code execution. The plugin is not listed in the CISA KEV catalog, but the high CVSS score of 8.8 and lack of a patch warrant immediate remediation.
OpenCVE Enrichment