CVE-2026-13157
N/A
N/A
Summary
The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the uploads directory.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Theme Demo Import | 0 <= 1.1.3 | affected |
Weaknesses
- CWE-434 Unrestricted Upload of File with Dangerous Type
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.