CyberRota Analysis
AI-GeneratedThe Everest Toolkit WordPress plugin versions up to 1.2.3 are vulnerable due to inadequate validation of file types during demo-content import, allowing high-privilege users, including non-super-admin site administrators on multisite installations, to upload executable PHP files to the uploads directory. This flaw can lead to remote code execution, potentially compromising the entire WordPress site. WordPress administrators and security teams should prioritize addressing this vulnerability to mitigate the risk of exploitation.
Original NVD Description
The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the uploads directory.