WordPress Plugin Vulnerabilities

WP Import Export Lite < 3.9.33 - Contributor+ Stored DOM XSS via Custom Field Names

Description

The plugin does not escape custom field names retrieved from the database before inserting them into the DOM of one of its administration screens, allowing users with a role as low as contributor to perform Stored XSS attacks which will trigger in the browser of a high privileged user, such as an administrator, viewing that screen.

Proof of Concept

Affects Plugins

Fixed in 3.9.33

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
mak3bread(Minseong Kim)
Submitter
mak3bread(Minseong Kim)
Verified
Yes

Timeline

Publicly Published
2026-09-14 (about 2 days ago)
Added
2026-09-14 (about 1 day ago)
Last Updated
2026-09-14 (about 1 day ago)

Other