File Upload Vulnerability in Demo Import Plugin by WordPress
CVE-2026-13157
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 1 August 2026
Badges
What is CVE-2026-13157?
The Demo Import plugin for WordPress, up to version 1.1.3, exhibits a significant security flaw that permits high-privilege users, typically Administrators, to upload arbitrary files without proper validation. The plugin disables the WordPress file-type test during the demo-content import process, leading to the risk of malicious executable PHP files being uploaded to the site's uploads directory. This vulnerability can potentially compromise site security and allow attackers to execute harmful code, thereby putting sensitive data at risk.
Affected Version(s)
Theme Demo Import 0 <= 1.1.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.