CVE-2026-76557: WP Import Export Lite < 3.9.33 - Authenticated SQLi via Import Options

Published Sep 16, 2026
·
Updated

The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some import configuration values before using them in SQL statements, allowing users whose role an administrator has granted the WP Import Export Lite WordPress plugin before 3.9.33's import permission to perform SQL injection attacks.

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade WP Import Export Lite WordPress plugin to a version that resolves this vulnerability.

    Fixed in 3.9.33

Event History

Sep 16, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must be a user who has been granted the WP Import Export Lite import permission by an administrator. The issue is therefore limited to authenticated users with that specific plugin permission.

2

Are default WordPress user roles necessarily affected?

The available information does not identify any default WordPress role as having the required permission. Exposure depends on whether an administrator granted the plugin's import permission to a user.

3

What version resolves the issue?

The issue affects WP Import Export Lite versions before 3.9.33. Updating to version 3.9.33 or later removes the affected version range.

4

What can be done if updating is not immediately possible?

Review and remove WP Import Export Lite import permission from users who do not strictly require it. Restricting that permission reduces the set of authenticated users able to attempt exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203