CVE-2026-76554 PUBLISHED

WP Import Export Lite < 3.9.35 - Authenticated Privilege Escalation via User Import

Assigner: WPScan
Reserved: 19.08.2026 Published: 19.09.2026 Updated: 19.09.2026

The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to create or modify user accounts and assign roles, allowing users granted a delegated WP Import Export Lite WordPress plugin before 3.9.35 permission, who cannot otherwise manage users, to create administrator accounts and to overwrite the credentials and role of existing accounts, including administrators.

Product Status

Vendor Unknown
Product WP Import Export Lite
Versions Default: unaffected
  • affected from 0 to 3.9.35 (excl.)

Credits

  • mak3bread(Minseong Kim) finder
  • WPScan coordinator

References

Problem Types

  • CWE-269 Improper Privilege Management CWE