---
id: CVE-2026-76551
title: >-
  The WP Import Export Lite WordPress plugin before 3.9.33 does not restrict
  which PHP function may be applied to exported field values, allowing users
  granted its export permission to have arbitrary functions invoked on values
  they contro…
summary: >-
  The WP Import Export Lite WordPress plugin before 3.9.33 does not restrict
  which PHP function may be applied to exported field values, allowing users
  granted its export permission to have arbitrary functions invoked on values
  they contro…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
product: WP Import Export Lite
affected:
  - wp_import_export_lite < 3.9.33
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T13:16:45.787'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76551'
references:
  - url: 'https://wpscan.com/vulnerability/1ad0c536-cebd-40d2-b6a9-48c5c76e972c/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T12:23:08.466526Z'
epss: 0.00822
epssPercentile: 0.55451
ingestedAt: '2026-09-16T06:51:06.243Z'
---

## Overview

The WP Import Export Lite WordPress plugin before 3.9.33 does not restrict which PHP function may be applied to exported field values, allowing users granted its export permission to have arbitrary functions invoked on values they control, leading to remote code execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
