What is CVE-2026-13157?
The Demo Import WordPress plugin up to version 1.1.3 allows high-privilege users to upload executable files due to disabled file type validation during demo content imports. This affects sites where administrators can exploit this to compromise the server. The plugin should be updated or removed immediately.
Azərbaycanca: WordPress-in Demo Import pluginin 1.1.3 versiyasına qədər olan boşluq yüksək səlahiyyətli istifadəçilərə, demək olar ki, icra edilə bilən fayllar yükləməyə imkan verir. Bu zəiflik fayl tipi yoxlamasının söndürülməsi səbəbindən baş verir. Plugin-i dərhal son versiyaya yeniləmək və ya dayandırmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
Why does the CVE-2026-13157 vulnerability occur in the WordPress Demo Import plugin?
This vulnerability occurs due to disabled file type validation.
Who can upload malicious files by exploiting CVE-2026-13157?
High-privilege users can upload executable files.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.