Directory Traversal Vulnerability in Post Export Import with Media Plugin for WordPress
CVE-2026-104763

4.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 October 2026

What is CVE-2026-104763?

The Post Export Import with Media plugin for WordPress is susceptible to a Directory Traversal vulnerability that exists in all versions up to 1.17.1. This flaw can be exploited by authenticated users with administrator privileges who can manipulate the 'file_path' parameter. By uploading a specially crafted ZIP archive containing a media_metadata.json file, attackers can introduce path traversal sequences to read files outside the intended directory. This compromise can lead to the unauthorized exposure of sensitive data stored on the server, thus putting the site's security at risk.

Affected Version(s)

Post Export Import with Media 0 <= 1.17.1

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.