CVE-2026-76557: WP Import Export Lite < 3.9.33 - Authenticated SQLi via Import Options
The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some import configuration values before using them in SQL statements, allowing users whose role an administrator has granted the WP Import Export Lite WordPress plugin before 3.9.33's import permission to perform SQL injection attacks.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WP Import Export Lite WordPress pluginto a version that resolves this vulnerability.Fixed in 3.9.33
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be a user who has been granted the WP Import Export Lite import permission by an administrator. The issue is therefore limited to authenticated users with that specific plugin permission.
Are default WordPress user roles necessarily affected?
The available information does not identify any default WordPress role as having the required permission. Exposure depends on whether an administrator granted the plugin's import permission to a user.
What version resolves the issue?
The issue affects WP Import Export Lite versions before 3.9.33. Updating to version 3.9.33 or later removes the affected version range.
What can be done if updating is not immediately possible?
Review and remove WP Import Export Lite import permission from users who do not strictly require it. Restricting that permission reduces the set of authenticated users able to attempt exploitation.