PT-2025-31913 · WordPress · Wp Import Export Lite

Vincent Fourcade

·

Published

2025-08-05

·

Updated

2025-08-05

·

CVE-2025-6207

CVSS v3.1
7.5
VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions:

WP Import Export Lite versions up to and including 3.9.28

Description:

The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `wpie tempalte import` function. This allows authenticated attackers with Subscriber-level access and above, and permissions granted by an Administrator, to upload arbitrary files to the affected site's server, potentially enabling remote code execution.

Recommendations:

Update WP Import Export Lite to a version later than 3.9.28.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-6207

Affected Products

Wp Import Export Lite