{"api_version":"1","generated_at":"2026-09-16T07:44:19+00:00","cve":"CVE-2026-76555","urls":{"html":"https://cve.report/CVE-2026-76555","api":"https://cve.report/api/cve/CVE-2026-76555.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-76555","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-76555"},"summary":{"title":"WP Import Export Lite < 3.9.33 - Authenticated Sensitive File Disclosure via Existing File Import Path Traversal","description":"The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a user-supplied file path before reading it and copying it into a publicly accessible directory, allowing any user whose role an administrator has granted the WP Import Export Lite WordPress plugin before 3.9.33's import permission to disclose sensitive files from the server, including files located outside the web root. The same code path also relaxes the file-system permissions of any path it is given, whether or not the copy succeeds.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-09-16 06:16:32","updated_at":"2026-09-16 06:16:32"},"problem_types":["CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/aadc28e6-6176-45ca-80b6-a8186fba835f/","name":"https://wpscan.com/vulnerability/aadc28e6-6176-45ca-80b6-a8186fba835f/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-76555","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76555","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"WP Import Export Lite","version":"affected 3.9.33 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Hasyros","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"WP Import Export Lite","vendor":"Unknown","versions":[{"lessThan":"3.9.33","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Hasyros"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a user-supplied file path before reading it and copying it into a publicly accessible directory, allowing any user whose role an administrator has granted the WP Import Export Lite WordPress plugin before 3.9.33's import permission to disclose sensitive files from the server, including files located outside the web root. The same code path also relaxes the file-system permissions of any path it is given, whether or not the copy succeeds."}],"problemTypes":[{"descriptions":[{"description":"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-16T06:00:11.083Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/aadc28e6-6176-45ca-80b6-a8186fba835f/"}],"source":{"discovery":"EXTERNAL"},"title":"WP Import Export Lite < 3.9.33 - Authenticated Sensitive File Disclosure via Existing File Import Path Traversal","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-76555","datePublished":"2026-09-16T06:00:11.083Z","dateReserved":"2026-08-19T12:52:43.815Z","dateUpdated":"2026-09-16T06:00:11.083Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-16 06:16:32","lastModifiedDate":"2026-09-16 06:16:32","problem_types":["CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"76555","Ordinal":"1","Title":"WP Import Export Lite < 3.9.33 - Authenticated Sensitive File Di","CVE":"CVE-2026-76555","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"76555","Ordinal":"1","NoteData":"The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a user-supplied file path before reading it and copying it into a publicly accessible directory, allowing any user whose role an administrator has granted the WP Import Export Lite WordPress plugin before 3.9.33's import permission to disclose sensitive files from the server, including files located outside the web root. The same code path also relaxes the file-system permissions of any path it is given, whether or not the copy succeeds.","Type":"Description","Title":"WP Import Export Lite < 3.9.33 - Authenticated Sensitive File Di"}]}}}