OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-76554

HIGH · CVSS 7.2 EPSS 0.46%

Source: NVD + CISA KEV + EPSS · Published 2026-09-19 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The WP Import Export Lite plugin for WordPress versions prior to 3.9.35 is vulnerable due to insufficient user permission verification during import operations, enabling unauthorized users to create administrator accounts and modify existing user roles and credentials. This flaw poses a significant security risk as it allows individuals without proper privileges to gain elevated access, potentially compromising the entire WordPress site. WordPress site administrators and security teams should prioritize this vulnerability to prevent unauthorized account management and ensure proper access controls are enforced.

CVE
CVE-2026-76554
Severity
HIGH
CVSS
7.2
EPSS
0.46%
WordPress

Original NVD Description

The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to create or modify user accounts and assign roles, allowing users granted a delegated WP Import Export Lite WordPress plugin before 3.9.35 permission, who cannot otherwise manage users, to create administrator accounts and to overwrite the credentials and role of existing accounts, including administrators.