Review
Demo Import
CVE published 2026-08-01
CVE-2026-13157
The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import, allowing high-privilege users to upload executable PHP files to the uploads directory. This vulnerability can be exploited by high-privilege users, including non-super-admin site administrators on multisite, to potentially execute arbitrary code on the server. The plugin's failure to pro [truncated]