CVE-2026-76550
The WP Import Export Lite WordPress plugin before 3.9.34 does not validate a user-supplied output path when writing export files, allowing users granted its export permission to write files with arbitrary names to arbitrary locations on the server, leading to remote code execution.
- Published Sep 16, 2026
- CVSS 7.2 high
- 0.8% chance of exploitation in the next 30 days (EPSS)
- A fix is available