CVE-2026-76552

The WP Import Export Lite WordPress plugin before 3.9.33 does not validate the type, extension or content of files it retrieves from a user-supplied URL during import, allowing users granted its import permission to store arbitrary files, including executable ones, on the server and achieve remote code execution.

  • Published Sep 16, 2026
  • CVSS 8.8 high
  • 0.7% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-76552 at the National Vulnerability Database