CVE-2026-76554

HIGH CVSS 3.1: 7.2 EPSS 0.46%
Updated Sep 21, 2026
Unknown
Parameter Value
CVSS 7.2 (HIGH)
Affected Versions before 3.9.35
Type CWE-269 (Improper Privilege Management), CWE-269 Improper Privilege Management
Vendor Unknown
Public PoC No

The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to create or modify user accounts and assign roles, allowing users granted a delegated WP Import Export Lite WordPress plugin before 3.9.35 permission, who cannot otherwise manage users, to create administrator accounts and to overwrite the credentials and role of existing accounts, including administrators.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
High
Admin privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products

unknown:wp import export lite