WordPress · Wp Import Export Lite · CVE-2026-76555
**Name of the Vulnerable Software and Affected Versions**
WP Import Export Lite WordPress plugin versions prior to 3.9.33
**Description**
Insufficient validation of user-supplied file paths allows users with import permissions to disclose sensitive files from the server, including those located outside the web root. The process involves reading a file and copying it into a publicly accessible directory. Additionally, the affected code path modifies and relaxes the file-system permissions of any provided path, regardless of whether the copy operation is successful.
**Recommendations**
Update WP Import Export Lite WordPress plugin to version 3.9.33 or later.