The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some export filter values before using them in SQL statements, allowing users holding its export permission, which administrators have by default and may also grant to lower roles, to perform SQL injection attacks.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-16 06:16
Updated : 2026-09-16 20:25
NVD link : CVE-2026-76556
Mitre link : CVE-2026-76556
CVE.ORG link : CVE-2026-76556
JSON object : View
Products Affected
No product.
CWE
No CWE.
