CVE-2026-76550: WP Import Export Lite < 3.9.34 - Authenticated RCE via Export Template Path Traversal
The WP Import Export Lite WordPress plugin before 3.9.34 does not validate a user-supplied output path when writing export files, allowing users granted its export permission to write files with arbitrary names to arbitrary locations on the server, leading to remote code execution.
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated and have the WP Import Export Lite export permission. Users without that permission are not described as able to exploit it.
What capability does exploitation provide?
A permitted user can supply an output path that is not validated, causing export files to be written with arbitrary names in arbitrary server locations. This can lead to remote code execution.
Which plugin versions are affected?
WP Import Export Lite versions before 3.9.34 are affected. Version 3.9.34 or later is not identified as affected by the provided information.