CVE-2026-76553
N/A
N/A
Summary
The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from stored, user-supplied data before recursively deleting the directory it resolves to, allowing users to whom an administrator has delegated a WP Import Export Lite WordPress plugin before 3.9.33 capability to delete arbitrary directories, and every file within them, including outside the web root.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | WP Import Export Lite | 0 < 3.9.33 | affected |
Weaknesses
- CWE-73 External Control of File Name or Path
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.