CVE-2026-76551

The WP Import Export Lite WordPress plugin before 3.9.33 does not restrict which PHP function may be applied to exported field values, allowing users granted its export permission to have arbitrary functions invoked on values they control, leading to remote code execution.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-16 06:16

Updated : 2026-09-16 20:25


NVD link : CVE-2026-76551

Mitre link : CVE-2026-76551

CVE.ORG link : CVE-2026-76551


JSON object : View

Products Affected

No product.

CWE

No CWE.