---
id: CVE-2026-76559
title: >-
  The WP Import Export Lite WordPress plugin before 3.9.33 does not properly
  validate URLs before requesting them during the import process, allowing users
  with the import capability, which administrators hold by default, to make the
  site …
summary: >-
  The WP Import Export Lite WordPress plugin before 3.9.33 does not properly
  validate URLs before requesting them during the import process, allowing users
  with the import capability, which administrators hold by default, to make the
  site …
severity: medium
cvss: 4.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N'
cwe:
  - CWE-918
product: WP Import Export Lite
affected:
  - wp_import_export_lite < 3.9.33
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T13:16:46.960'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76559'
references:
  - url: 'https://wpscan.com/vulnerability/62e27c51-95c7-407b-81aa-85757130adb9/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T12:21:25.348541Z'
epss: 0.00286
epssPercentile: 0.21436
ingestedAt: '2026-09-16T06:51:06.246Z'
---

## Overview

The WP Import Export Lite WordPress plugin before 3.9.33 does not properly validate URLs before requesting them during the import process, allowing users with the import capability, which administrators hold by default, to make the site issue requests to internal hosts and services and read their responses. This is an incomplete fix for CVE-2026-11397.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
