File Upload Vulnerability in Demo Import Plugin by WordPress
CVE-2026-13157

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-13157?

The Demo Import plugin for WordPress, up to version 1.1.3, exhibits a significant security flaw that permits high-privilege users, typically Administrators, to upload arbitrary files without proper validation. The plugin disables the WordPress file-type test during the demo-content import process, leading to the risk of malicious executable PHP files being uploaded to the site's uploads directory. This vulnerability can potentially compromise site security and allow attackers to execute harmful code, thereby putting sensitive data at risk.

Affected Version(s)

Theme Demo Import 0 <= 1.1.3

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Huynh Kien Minh
WPScan
.