Impact
The WP Import Export Lite WordPress plugin before version 3.9.33 does not validate URLs that are supplied by users with import capability. Adversaries who have that capability, which administrators normally hold, can supply arbitrary URLs during the import process. The plugin then forwards the request to the specified host, retrieves the response, and returns it to the user. This flaw allows the attacker to compel the site to reach internal hosts or services and read their responses, effectively leaking internal network data or allowing probing of internal resources.
Affected Systems
Any website running the WP Import Export Lite plugin version earlier than 3.9.33 is affected. The plugin operates within WordPress, and the import functionality is by default available to administrators. The absence of vendor information beyond the plugin name means that any site using this plugin without a patch is potentially vulnerable.
Risk and Exploitability
The EPSS score is indicated as less than 1 %, suggesting a low probability of exploitation at the current time. The vulnerability is not listed in the CISA KEV catalog, which further implies limited known exploitation. However, because the flaw enables an internal SSRF that can expose sensitive information, the risk to confidentiality remains significant. Exploitation would require the attacker to have administrative privileges or to compromise an administrator account, after which they can supply malicious import URLs to collect internal responses. The lack of a publicly available the nature of the SSRF indicates that the flaw should be treated with high severity when in a production environment.
OpenCVE Enrichment