Impact
The WP Import Export Lite WordPress plugin before version 3.9.33 accepts a user‑supplied file path without validation, then copies that file into a publicly accessible directory. This flaw permits an attacker with the plugin’s import permission to read arbitrary files on the server, including files located outside the web root. Additionally, the code relaxes file‑system permissions on the target path regardless of the copy outcome, potentially exposing the system to further misuse.
Affected Systems
The vulnerability affects installations of the WP Import Export Lite plugin running any version earlier than 3.9.33. No other vendors or product variants are explicitly listed. The issue is present a standard WordPress plugin.
Risk and Exploitability
This flaw is only exploitable by users who have been granted the import privilege by an administrator, which implies authenticated access. The EPSS score is below 1%, indicating a low probability of current exploitation, and the issue is not listed in the CISA KEV catalog. Nonetheless, because the attacker can obtain confidential files and potentially alter file permissions, the risk becomes significant if the attacker can obtain such a user role. The path traversal flaw allows disclosure of internal files that may contain sensitive configuration or credentials, providing an avenue for broader compromise.
OpenCVE Enrichment