plugin

Wp Import Export Lite Vulnerabilities

13 known security issues reported for the Wp Import Export Lite WordPress plugin. Most recent disclosed Jul 2, 2026.

4 high 2 medium

Running Wp Import Export Lite on your site? Check whether your installed version is affected.

Scan your site free

WP Import Export Lite <= 3.9.30 - Authenticated (Administrator+) Server-Side Request Forgery via 'file_url' Parameter

medium

The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and including 3.9.30 via the wpie_import_upload_file_from_url AJAX action. The plugin's URL downloader first calls wp_safe_remote_get() (which correctly blocks private/reserved IP ranges), but when that cal...

CVSS:
5.5
Affected:
up to 3.9.30
Fixed in:
3.9.31
Disclosed:
Jul 2, 2026

CVE-2026-11397 on NVD →

WP Import Export Lite <= 3.9.29 - Authenticated (Subscriber+) Arbitrary File Upload

high

The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_parse_upload_data' function in all versions up to, and including, 3.9.29. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions gr...

CVSS:
7.5
Affected:
up to 3.9.29
Fixed in:
3.9.30
Disclosed:
Aug 4, 2025

CVE-2025-5061 on NVD →

WP Import Export Lite <= 3.9.28 - Authenticated (Subscriber+) Arbitrary File Upload

high

The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_tempalte_import' function in all versions up to, and including, 3.9.28. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions gran...

CVSS:
7.5
Affected:
up to 3.9.28
Fixed in:
3.9.29
Disclosed:
Aug 4, 2025

CVE-2025-6207 on NVD →

WP Import Export Lite <= 3.9.27 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting

medium

The WP Import Export Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpiePreviewData’ function in all versions up to, and including, 3.9.27 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and ab...

CVSS:
6.4
Affected:
up to 3.9.27
Fixed in:
3.9.28
Disclosed:
Apr 21, 2025

CVE-2025-2839 on NVD →

WP Import Export Lite [wp-import-export-lite] < 3.9.27

unknown

[en] Deserialization of Untrusted Data vulnerability in VJInfotech WP Import Export Lite.This issue affects WP Import Export Lite: from n/a through 3.9.26.

Affected:
up to 3.9.27
Fixed in:
3.9.27
Disclosed:
Apr 7, 2024

CVE-2024-31308 on NVD →

WP Import Export Lite <= 3.9.26 - Authenticated (Administrator+) PHP Object Injection

high

The WP Import Export Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.9.26 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present i...

CVSS:
7.2
Affected:
up to 3.9.26
Fixed in:
3.9.27
Disclosed:
Apr 5, 2024

CVE-2024-31308 on NVD →

WP Import Export Lite [wp-import-export-lite] < 3.9.16

unknown

[en] The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file. This made it possible for unauthentica...

Affected:
up to 3.9.16
Fixed in:
3.9.16
Disclosed:
Jan 18, 2022

CVE-2022-0236 on NVD →

WP Import Export Lite & WP Import Export <= 3.9.15 - Unauthenticated Sensitive Data Disclosure

high

The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file. This made it possible for unauthenticated a...

CVSS:
7.5
Affected:
up to 3.9.15
Fixed in:
3.9.16
Disclosed:
Jan 14, 2022

CVE-2022-0236 on NVD →

WP Import Export Lite [wp-import-export-lite] < 3.9.5

unknown

The plugin does not have any CSRF and authorisation checks done in the wpie_ext_save_extension_data AJAX action, nor do perform any validation on the option to be updated. As a result, any authenticated user such as subscriber, or an unauthenticated attacker via a CSRF could update any of the blog options (set to the s...

Affected:
up to 3.9.5
Fixed in:
3.9.5

WP Import Export Lite [wp-import-export-lite] < 3.9.5

unknown

The plugin does not have any CSRF and authorisation checks done in wpie_ext_save_extensions AJAX action. This could allow any authenticated user such as subscriber, or an unauthenticated attacker via a CSRF to set the extensions to be used by the plugin, as well as disable all of them

Affected:
up to 3.9.5
Fixed in:
3.9.5

WP Import Export Lite [wp-import-export-lite] < 3.9.28

unknown
Affected:
up to 3.9.28
Fixed in:
3.9.28

CVE-2025-2839 on NVD →

WP Import Export Lite [wp-import-export-lite] < 3.9.29

unknown
Affected:
up to 3.9.29
Fixed in:
3.9.29

CVE-2025-6207 on NVD →

WP Import Export Lite [wp-import-export-lite] < 3.9.30

unknown
Affected:
up to 3.9.30
Fixed in:
3.9.30

CVE-2025-5061 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database