CVE-2026-76550

The WP Import Export Lite WordPress plugin before 3.9.34 does not validate a user-supplied output path when writing export files, allowing users granted its export permission to write files with arbitrary names to arbitrary locations on the server, leading to remote code execution.

  • Published Sep 16, 2026
  • CVSS 7.2 high
  • 0.8% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-76550 at the National Vulnerability Database