WP Import Export Lite <= 3.9.30 - Authenticated (Administrator+) Server-Side Request Forgery via 'file_url' Parameter
medium
The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and including 3.9.30 via the wpie_import_upload_file_from_url AJAX action. The plugin's URL downloader first calls wp_safe_remote_get() (which correctly blocks private/reserved IP ranges), but when that cal...
- CVSS:
- 5.5
- Affected:
- up to 3.9.30
- Fixed in:
- 3.9.31
- Disclosed:
- Jul 2, 2026
CVE-2026-11397 on NVD →
WP Import Export Lite <= 3.9.29 - Authenticated (Subscriber+) Arbitrary File Upload
high
The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_parse_upload_data' function in all versions up to, and including, 3.9.29. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions gr...
- CVSS:
- 7.5
- Affected:
- up to 3.9.29
- Fixed in:
- 3.9.30
- Disclosed:
- Aug 4, 2025
CVE-2025-5061 on NVD →
WP Import Export Lite <= 3.9.28 - Authenticated (Subscriber+) Arbitrary File Upload
high
The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_tempalte_import' function in all versions up to, and including, 3.9.28. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions gran...
- CVSS:
- 7.5
- Affected:
- up to 3.9.28
- Fixed in:
- 3.9.29
- Disclosed:
- Aug 4, 2025
CVE-2025-6207 on NVD →
WP Import Export Lite <= 3.9.27 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
medium
The WP Import Export Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpiePreviewData’ function in all versions up to, and including, 3.9.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and ab...
- CVSS:
- 6.4
- Affected:
- up to 3.9.27
- Fixed in:
- 3.9.28
- Disclosed:
- Apr 21, 2025
CVE-2025-2839 on NVD →
WP Import Export Lite [wp-import-export-lite] < 3.9.27
unknown
[en] Deserialization of Untrusted Data vulnerability in VJInfotech WP Import Export Lite.This issue affects WP Import Export Lite: from n/a through 3.9.26.
- Affected:
- up to 3.9.27
- Fixed in:
- 3.9.27
- Disclosed:
- Apr 7, 2024
CVE-2024-31308 on NVD →
WP Import Export Lite <= 3.9.26 - Authenticated (Administrator+) PHP Object Injection
high
The WP Import Export Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.9.26 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present i...
- CVSS:
- 7.2
- Affected:
- up to 3.9.26
- Fixed in:
- 3.9.27
- Disclosed:
- Apr 5, 2024
CVE-2024-31308 on NVD →
WP Import Export Lite [wp-import-export-lite] < 3.9.16
unknown
[en] The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file. This made it possible for unauthentica...
- Affected:
- up to 3.9.16
- Fixed in:
- 3.9.16
- Disclosed:
- Jan 18, 2022
CVE-2022-0236 on NVD →
WP Import Export Lite & WP Import Export <= 3.9.15 - Unauthenticated Sensitive Data Disclosure
high
The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file. This made it possible for unauthenticated a...
- CVSS:
- 7.5
- Affected:
- up to 3.9.15
- Fixed in:
- 3.9.16
- Disclosed:
- Jan 14, 2022
CVE-2022-0236 on NVD →
WP Import Export Lite [wp-import-export-lite] < 3.9.5
unknown
The plugin does not have any CSRF and authorisation checks done in the wpie_ext_save_extension_data AJAX action, nor do perform any validation on the option to be updated. As a result, any authenticated user such as subscriber, or an unauthenticated attacker via a CSRF could update any of the blog options (set to the s...
- Affected:
- up to 3.9.5
- Fixed in:
- 3.9.5
WP Import Export Lite [wp-import-export-lite] < 3.9.5
unknown
The plugin does not have any CSRF and authorisation checks done in wpie_ext_save_extensions AJAX action. This could allow any authenticated user such as subscriber, or an unauthenticated attacker via a CSRF to set the extensions to be used by the plugin, as well as disable all of them
- Affected:
- up to 3.9.5
- Fixed in:
- 3.9.5
WP Import Export Lite [wp-import-export-lite] < 3.9.28
unknown
- Affected:
- up to 3.9.28
- Fixed in:
- 3.9.28
CVE-2025-2839 on NVD →
WP Import Export Lite [wp-import-export-lite] < 3.9.29
unknown
- Affected:
- up to 3.9.29
- Fixed in:
- 3.9.29
CVE-2025-6207 on NVD →
WP Import Export Lite [wp-import-export-lite] < 3.9.30
unknown
- Affected:
- up to 3.9.30
- Fixed in:
- 3.9.30
CVE-2025-5061 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database