Impact
The WP Import Export Lite WordPress plugin before version 3.9.33 does not properly sanitise some export filter values before using them in SQL statements, permitting use of those values in vulnerable queries. This flaw allows a user who possesses export privileges to inject arbitrary SQL commands, potentially enabling read, update, or delete operations against the WordPress database.
Affected Systems
Any WordPress site running the WP Import Export Lite plugin with a version earlier than 3.9.33 is affected. By default administrators have export permission and site owners can extend that permission to other user roles, broadening the attack surface for the vulnerability.
Risk and Exploitability
The EPSS score is listed as < 1 %, indicating that public data suggests a low exploitation probability. The flaw is not currently catalogued in the CISA KEV list. However, because the vulnerability requires only an authenticated export privilege—which is typically granted to administrators and sometimes to lower-level roles—any attacker who can gain such access can exploit the SQL injection flaw to compromise the integrity and confidentiality of the WordPress database. No CVSS score is publicly available, but the nature of the flaw and the potential data exposure warrant a high severity classification for environments where export permissions are permissively assigned.
OpenCVE Enrichment