---
id: CVE-2026-76554
title: >-
  The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that
  the user running an import is permitted to create or modify user accounts and
  assign roles, allowing users granted a delegated WP Import Export Lite
  WordPress …
summary: >-
  The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that
  the user running an import is permitted to create or modify user accounts and
  assign roles, allowing users granted a delegated WP Import Export Lite
  WordPress …
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
product: WP Import Export Lite
affected:
  - wp_import_export_lite < 3.9.35
published: '2026-09-19'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T13:34:57.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76554'
references:
  - url: 'https://wpscan.com/vulnerability/e28c78be-e2f7-4580-9f16-488955914be3/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00257
epssPercentile: 0.17617
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-19T13:15:15.822857Z'
ingestedAt: '2026-09-19T06:59:13.117Z'
---

## Overview

The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to create or modify user accounts and assign roles, allowing users granted a delegated WP Import Export Lite WordPress plugin before 3.9.35 permission, who cannot otherwise manage users, to create administrator accounts and to overwrite the credentials and role of existing accounts, including administrators.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
