Impact
The WP Import Export Lite WordPress plugin before version 3.9.33 accepts a user‑supplied file path without validation, then copies that file into a publicly accessible directory. This flaw permits an attacker with the plugin’s import permission to read arbitrary files on the server, including files located outside the web root. Additionally, the code relaxes file‑system permissions on the target path regardless of the copy outcome, potentially exposing the system to further misuse. This is a path traversal vulnerability (CWE-22).
Affected Systems
The vulnerability affects installations of the WP Import Export Lite plugin running any version earlier than 3.9.33. No other vendors or product variants are explicitly listed. The issue is present a standard WordPress plugin.
Risk and Exploitability
This flaw is only exploitable by users who have been granted the import privilege by an administrator, meaning it requires authenticated access. The attacker can supply an arbitrary file path that traverses directories and is copied into a publicly accessible location, enabling the disclosure of any readable file on the server, including files located outside the web root. Because the threshold for exploitation is the import permission, the attack vector is an authenticated user who can upload a crafted file path. The CVSS score of 6.8 indicates a medium severity vulnerability; the EPSS score of less than 1% shows that the likelihood of exploitation is currently low, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the ability to read arbitrary files and to relax file‑system permissions on the target path means that once an authenticated user is compromised, the attacker can obtain confidential data and possibly modify file permissions to gain further persistence or enable additional attacks.
OpenCVE Enrichment