Impact
The WP Import Export Lite plugin before 3.9.33 fails to sanitize and escape certain import configuration values before incorporating them into SQL statements. This flaw allows a user with an import role granted by the plugin’s administrator to inject arbitrary SQL. In practice, the attacker could read, modify, or delete data in the integrity and confidentiality of the site's contents.
Affected Systems
The vulnerability affects the WP Import Export Lite WordPress plugin versions earlier than 3.9.33. Administrators who have granted the plugin’s import permission to other users create an environment in which these users can exploit the flaw. No other versions or products are listed as affected in the available data.
Risk and Exploitability
The EPSS score for this vulnerability is less than 1%, indicating a low probability of exploitation in the wild, and it is not listed in CISA’s KEV catalog. However, SQL injection is inherently a high‑impact vulnerability, capable of compromising both the confidentiality and integrity of the database. The attack vector requires authenticated access to the plugin’s import feature, limiting the potential attacker set to users with administrative privileges assigned within the plugin. Nonetheless, the damage that can be achieved if exploited is significant, warranting remediation as a priority.
OpenCVE Enrichment