Description
The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from stored, user-supplied data before recursively deleting the directory it resolves to, allowing users to whom an administrator has delegated a WP Import Export Lite WordPress plugin before 3.9.33 capability to delete arbitrary directories, and every file within them, including outside the web root.
Published: 2026-09-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary Directory Deletion
Action: Apply Patch
AI Analysis

Impact

WP Import Export Lite, a WordPress plugin, fails to validate a path that comes from stored, user‑supplied data before recursively deleting the directory that resolves to that path. This flaw arises from an uncontrolled use of path information leading to path traversal and insecure deletion (CWE-73). An authenticated user with delegated import‑export rights can cause the plugin to delete any directory referenced in the stored data, even directories and files located outside the web root. This removal can destroy website content, database backups, or server configuration files, severely compromising integrity and availability.

Affected Systems

Any WordPress site running WP Import Export Lite versions earlier than 3.9.33 is vulnerable, including those where site administrators have delegated import‑export privileges to non‑admin users. The issue resides solely within the plugin’s code, and no external vendor modifies it.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score of <1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, meaning no widespread exploits have been documented. Nevertheless, the ability to delete arbitrary directories, including critical system files, represents a severe potential impact, so sites using the affected plugin should mitigate promptly.

Generated by OpenCVE AI on September 20, 2026 at 05:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update WP Import Export Lite to version 3.9.33 or later, which removes the deletion flaw.
  • Revoke or restrict delegated import‑export permissions for users who do not need them, so that only site administrators can trigger deletion operations.
  • Configure restrictive file‑system permissions on directories that the plugin can access, limiting the scope of possible deletions.

Generated by OpenCVE AI on September 20, 2026 at 05:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-73
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22

Wed, 16 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from stored, user-supplied data before recursively deleting the directory it resolves to, allowing users to whom an administrator has delegated a WP Import Export Lite WordPress plugin before 3.9.33 capability to delete arbitrary directories, and every file within them, including outside the web root.
Title WP Import Export Lite < 3.9.33 - Authenticated Arbitrary Directory Deletion via Template Path Traversal
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-17T12:40:59.330Z

Reserved: 2026-08-19T12:52:35.815Z

Link: CVE-2026-76553

cve-icon Vulnrichment

Updated: 2026-09-17T12:22:22.071Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T06:16:32.173

Modified: 2026-09-17T13:16:46.120

Link: CVE-2026-76553

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:15:16Z

Weaknesses
  • CWE-73

    External Control of File Name or Path