Description
The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to create or modify user accounts and assign roles, allowing users granted a delegated WP Import Export Lite WordPress plugin before 3.9.35 permission, who cannot otherwise manage users, to create administrator accounts and to overwrite the credentials and role of existing accounts, including administrators.
Published: 2026-09-19
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Authenticated Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The WP Import Export Lite WordPress plugin contains an internal permission check flaw: when performing a user import, the plugin does not confirm that the executing user has the authority to create or modify accounts and assign roles. This allows a user with any delegated import capability to create new administrator accounts or overwrite existing users, including administrators, thereby granting full site control to an attacker. The vulnerability is therefore categorized as an authenticated privilege escalation. The weakness aligns with CWE-269.

Affected Systems

Any WordPress installation that utilizes WP Import Export Lite version earlier than 3.9.35 is impacted. Users who have been granted delegated import permissions but otherwise lack user‑management rights are the actors who can exploit this flaw. Sites should review whether the plugin import feature is exposed to non‑administrator roles.

Risk and Exploitability

The CVSS score of 7.2 indicates a high severity, while the EPSS score of <1% suggests a low probability of exploitation in the wild; it is not listed in the CISA KEV catalog. The attack requires authenticated access to the import functionality, typically via a user who has been delegated the import capability. Once the import is triggered with a crafted payload, the attacker can elevate privileges by creating or replacing administrator accounts, resulting in full control of the WordPress site.

Generated by OpenCVE AI on September 20, 2026 at 00:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update WP Import Export Lite to version 3.9.35 or later
  • Configure the plugin so that only users with administrator privileges can access the import function by restricting the required capability
  • Continuously monitor WordPress user logs for unexpected creation or modification of administrator accounts and review audit logs for suspicious changes

Generated by OpenCVE AI on September 20, 2026 at 00:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions wp Import Export Lite
Vendors & Products Wordpress-extensions
Wordpress-extensions wp Import Export Lite

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-790

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Sat, 19 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-790

Sat, 19 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to create or modify user accounts and assign roles, allowing users granted a delegated WP Import Export Lite WordPress plugin before 3.9.35 permission, who cannot otherwise manage users, to create administrator accounts and to overwrite the credentials and role of existing accounts, including administrators.
Title WP Import Export Lite < 3.9.35 - Authenticated Privilege Escalation via User Import
References

Subscriptions

Wordpress-extensions Wp Import Export Lite
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-19T13:20:26.688Z

Reserved: 2026-08-19T12:52:37.640Z

Link: CVE-2026-76554

cve-icon Vulnrichment

Updated: 2026-09-19T13:13:20.808Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T07:16:32.540

Modified: 2026-09-21T13:34:57.127

Link: CVE-2026-76554

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:49:40Z

Weaknesses
  • CWE-269

    Improper Privilege Management