CVE-2026-76553: WP Import Export Lite < 3.9.33 - Authenticated Arbitrary Directory Deletion via Template Path Traversal

Published Sep 16, 2026
·
Updated

The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from stored, user-supplied data before recursively deleting the directory it resolves to, allowing users to whom an administrator has delegated a WP Import Export Lite WordPress plugin before 3.9.33 capability to delete arbitrary directories, and every file within them, including outside the web root.

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade WP Import Export Lite WordPress plugin to a version that resolves this vulnerability.

    Fixed in 3.9.33
  2. Compensating control

    Restrict/limit delegated capabilities for the WP Import Export Lite WordPress plugin so non-administrator users do not gain authority to exploit the authenticated arbitrary directory deletion (e.g., remove unnecessary delegated permissions).

Event History

Sep 16, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must be an authenticated user who has been delegated a WP Import Export Lite capability by an administrator. It is not described as exploitable by unauthenticated visitors.

2

What systems are affected?

WP Import Export Lite versions before 3.9.33 are affected. The vulnerable deletion can target directories outside the web root as well as files within those directories.

3

What is the impact of successful exploitation?

A permitted plugin user can use a path from stored user-supplied data to cause recursive deletion of an arbitrary resolved directory and all files it contains.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203