CVE-2026-76552
The WP Import Export Lite WordPress plugin before 3.9.33 does not validate the type, extension or content of files it retrieves from a user-supplied URL during import, allowing users granted its import permission to store arbitrary files, including executable ones, on the server and achieve remote code execution.
- Published Sep 16, 2026
- CVSS 8.8 high
- 0.7% chance of exploitation in the next 30 days (EPSS)
- A fix is available