Back

HIGH

WP Import Export (Lite) <= 3.9.15 Unauthenticated Sensitive Data Disclosure

Published Jan 18, 2022

Description

The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data disclosure due to a missing capability check on the download function wpie_process_file_download found in the ~/includes/classes/class-wpie-general.php file. This made it possible for unauthenticated attackers to download any imported or exported information from a vulnerable site which can contain sensitive information like user data. This affects versions up to, and including, 3.9.15.

Affected products

Remediation

Vendor solution

Update to version 3.9.16, or newer.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Jan 18, 2022
Updated Jan 31, 2025
Reserved Jan 14, 2022
CISA Vulnrichment
Updated Jan 31, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner n/a
Published n/a
Updated n/a
Exploited since n/a
Link n/a