CVE-2026-76554: WP Import Export Lite < 3.9.35 - Authenticated Privilege Escalation via User Import
The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to create or modify user accounts and assign roles, allowing users granted a delegated WP Import Export Lite WordPress plugin before 3.9.35 permission, who cannot otherwise manage users, to create administrator accounts and to overwrite the credentials and role of existing accounts, including administrators.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A user must have delegated permission to run WP Import Export Lite imports. They do not need normal WordPress user-management permissions.
What can an attacker do after exploiting it?
They can create administrator accounts or modify existing accounts' credentials and roles, including those of administrator accounts.
Are installations running version 3.9.35 affected?
The issue affects versions before 3.9.35. The provided information does not identify any affected configuration beyond granting a user delegated plugin import permission.