Impact
The WP Import Export Lite WordPress plugin contains an internal permission check flaw: when performing a user import, the plugin does not confirm that the executing user has the authority to create or modify accounts and assign roles. This allows a user with any delegated import capability to create new administrator accounts or overwrite existing users, including administrators, thereby granting full site control to an attacker. The vulnerability is therefore categorized as an authenticated privilege escalation. The weakness aligns with CWE-269.
Affected Systems
Any WordPress installation that utilizes WP Import Export Lite version earlier than 3.9.35 is impacted. Users who have been granted delegated import permissions but otherwise lack user‑management rights are the actors who can exploit this flaw. Sites should review whether the plugin import feature is exposed to non‑administrator roles.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity, while the EPSS score of <1% suggests a low probability of exploitation in the wild; it is not listed in the CISA KEV catalog. The attack requires authenticated access to the import functionality, typically via a user who has been delegated the import capability. Once the import is triggered with a crafted payload, the attacker can elevate privileges by creating or replacing administrator accounts, resulting in full control of the WordPress site.
OpenCVE Enrichment