CVE-2026-76554 Overview
CVE-2026-76554 is a privilege escalation vulnerability in the WP Import Export Lite WordPress plugin in versions before 3.9.35. The plugin fails to verify that a user running an import has permission to create or modify user accounts and assign roles. Any user granted the delegated import permission can abuse the import functionality to create new administrator accounts. The same flaw allows attackers to overwrite credentials and roles of existing accounts, including administrators, enabling full site takeover from a non-administrative role.
Critical Impact
Delegated plugin users can escalate to administrator, overwrite admin credentials, and gain full control of the WordPress site.
Affected Products
- WP Import Export Lite WordPress plugin versions prior to 3.9.35
- WordPress sites that have delegated import permissions to non-administrator roles
- Any WordPress deployment running the vulnerable plugin, regardless of hosting environment
Discovery Timeline
- 2026-09-19 - CVE-2026-76554 published to the National Vulnerability Database
- 2026-09-21 - Last updated in NVD database
Technical Details for CVE-2026-76554
Vulnerability Analysis
The vulnerability is a broken access control issue classified under [CWE-269] Improper Privilege Management. The WP Import Export Lite plugin allows administrators to delegate import capability to lower-privileged roles. The plugin's import routine processes user records contained in imported files without checking whether the requesting user holds the WordPress create_users, edit_users, or promote_users capabilities.
As a result, an authenticated user with only the delegated import capability can submit an import file containing arbitrary user records. The plugin will process those records, creating administrator accounts or overwriting the username, password hash, email, and role of existing accounts. This provides a direct path from a limited role to full administrative control over WordPress.
Root Cause
The root cause is the absence of capability checks around user-object handling during the import workflow. The plugin trusts that any user allowed to trigger an import is also allowed to manage users, conflating a plugin-level permission with WordPress core user-management capabilities.
Attack Vector
Exploitation requires an authenticated session with the delegated import permission. The attacker uploads a crafted import file containing user records with the administrator role or targeting an existing administrator username for overwrite. On import, the plugin creates or modifies those accounts, granting the attacker administrator credentials.
No user interaction beyond the attacker's own request is required. The attack occurs over the network against the WordPress admin interface. Refer to the WPScan Vulnerability Advisory for additional technical detail.
Detection Methods for CVE-2026-76554
Indicators of Compromise
- Unexpected WordPress accounts with the administrator role appearing in wp_users and wp_usermeta tables
- Modifications to existing administrator account email addresses, password hashes, or user_login values without corresponding admin activity
- Import job entries in WP Import Export Lite logs initiated by non-administrator accounts
- New administrator sessions originating from IP addresses previously associated with lower-privileged users
Detection Strategies
- Audit the wp_users table for accounts created or modified around import events, correlating with the initiating user ID
- Review WordPress action logs for user_register and profile_update hooks fired during plugin import operations
- Monitor HTTP POST requests to WP Import Export Lite admin-ajax or admin-post endpoints from users lacking manage_options
- Alert on role changes recorded in wp_capabilities usermeta that follow an import job
Monitoring Recommendations
- Enable WordPress activity logging that records user creation, role assignment, and password changes with the originating user ID
- Forward WordPress and web server logs to a centralized SIEM for correlation across import events and account changes
- Track plugin version inventory across WordPress deployments to identify hosts still running versions prior to 3.9.35
How to Mitigate CVE-2026-76554
Immediate Actions Required
- Upgrade WP Import Export Lite to version 3.9.35 or later on all WordPress installations
- Audit all administrator accounts and remove any that cannot be attributed to a legitimate user
- Rotate passwords and force re-authentication for all administrator accounts
- Review which roles hold the delegated WP Import Export Lite import capability and revoke it where unnecessary
Patch Information
The vendor addressed the vulnerability in WP Import Export Lite version 3.9.35 by adding capability checks that verify the current user holds WordPress user-management capabilities before processing user records during import. Site administrators should apply the update through the WordPress plugin dashboard or WP-CLI. See the WPScan Vulnerability Advisory for the fixed-version reference.
Workarounds
- Restrict the WP Import Export Lite import capability to administrator accounts only until the patch is applied
- Temporarily deactivate the plugin on sites where an immediate upgrade is not feasible
- Place the WordPress admin interface behind IP allow-listing or an authenticating reverse proxy to limit exposure
# Update WP Import Export Lite using WP-CLI
wp plugin update wp-import-export-lite --version=3.9.35
# Verify installed version
wp plugin get wp-import-export-lite --field=version
# List all administrator accounts for audit
wp user list --role=administrator --fields=ID,user_login,user_email,user_registered
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
