SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13157

HIGH · CVSS 7.2 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-08-01 · Last synced 2026-08-31

CyberRota Analysis

AI-Generated

The Demo Import plugin for WordPress versions up to 1.1.3 is vulnerable due to inadequate validation of uploaded file types, allowing high-privilege users, including administrators, to upload potentially malicious PHP files to the uploads directory. This could lead to remote code execution, compromising the integrity of the WordPress site. WordPress site administrators and security teams should prioritize this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-13157
Severity
HIGH
CVSS
7.2
EPSS
0.35%
WordPress

Original NVD Description

The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the uploads directory.