Impact
WP Import Export Lite, a WordPress plugin, fails to validate a path that comes from stored, user‑supplied data before recursively deleting the directory that resolves to that path. This flaw arises from an uncontrolled use of path information leading to path traversal and insecure deletion (CWE-73). An authenticated user with delegated import‑export rights can cause the plugin to delete any directory referenced in the stored data, even directories and files located outside the web root. This removal can destroy website content, database backups, or server configuration files, severely compromising integrity and availability.
Affected Systems
Any WordPress site running WP Import Export Lite versions earlier than 3.9.33 is vulnerable, including those where site administrators have delegated import‑export privileges to non‑admin users. The issue resides solely within the plugin’s code, and no external vendor modifies it.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of <1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, meaning no widespread exploits have been documented. Nevertheless, the ability to delete arbitrary directories, including critical system files, represents a severe potential impact, so sites using the affected plugin should mitigate promptly.
OpenCVE Enrichment