PT-2026-95753 · WordPress · Wp Import Export Lite
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WP Import Export Lite WordPress plugin versions prior to 3.9.35
Description
The plugin fails to verify if the user performing an import has the necessary permissions to create or modify user accounts and assign roles. This allows users with delegated permissions for the plugin, who lack general user management privileges, to create new administrator accounts or overwrite the credentials and roles of existing accounts, including those of administrators.
Recommendations
Update WP Import Export Lite WordPress plugin to version 3.9.35 or later.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Import Export Lite