CVE-2026-76557
Received Received - Intake

SQL Injection in WP Import Export Lite WordPress Plugin

Vulnerability report for CVE-2026-76557, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-16

Assigner: WPScan

Description

The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some import configuration values before using them in SQL statements, allowing users whose role an administrator has granted the WP Import Export Lite WordPress plugin before 3.9.33's import permission to perform SQL injection attacks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-16
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_import_export_lite wp_import_export_lite to 3.9.33 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an authenticated SQL injection vulnerability in the WP Import Export Lite WordPress plugin versions before 3.9.33. The plugin does not properly sanitize and escape import configuration values before using them in SQL statements. Users with the plugin's import permission, granted by an administrator, can exploit this to perform SQL injection attacks.

Detection Guidance

Check the installed version of the WP Import Export Lite plugin in your WordPress admin panel. If it is below 3.9.33, the system is vulnerable. Look for unusual database queries or errors in logs that may indicate SQL injection attempts.

Impact Analysis

An attacker with import permissions could manipulate the plugin to execute unauthorized SQL commands on your WordPress database. This may lead to data theft, unauthorized access, or complete database compromise. The impact depends on the database contents and user permissions.

Compliance Impact

This vulnerability could lead to unauthorized access or exposure of sensitive data, violating GDPR and HIPAA requirements for data protection and confidentiality. Organizations may face legal penalties, fines, or reputational damage if exploited.

Mitigation Strategies

Update the WP Import Export Lite plugin to version 3.9.33 or later immediately. If updating is not possible, consider disabling the plugin until an update is applied. Review user permissions to ensure only trusted users have import capabilities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76557. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart