Impact
WP Import Export Lite, a popular Word a path taken from stored, user‑supplied data before recursively deleting the directory it resolves to. An attacker can trigger this path traversal deletion routine and remove any directory chosen in the stored data, including directories and files outside the web site files, configuration data, or other stored content, directly impacting the integrity and availability of the affected WordPress installation. It is inferred that an attacker with delegated plugin privileges could supply crafted stored data to cause the deletion of arbitrary directories.
Affected Systems
Any WordPress site running WP Import Export Lite version earlier than 3.9.33 is vulnerable. The vendor is not identified beyond the plugin name, but the issue resides entirely in the plugin itself. Users who have been granted delegated import‑export rights—while not necessarily site administrators—can exercise the deletion functionality and thus pose a risk.
Risk and Exploitability
The attack requires authenticated access with delegated plugin privileges. The EPSS score indicates a very low exploitation probability (<1%), and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the potential damage—complete removal of arbitrary directories—is severe, suggesting that sites with the affected plugin should prioritize mitigation despite the low observed exploitation likelihood.
OpenCVE Enrichment