What is CVE-2026-13158?
The Everest Toolkit WordPress plugin (through version 1.2.3) fails to validate file types during demo-content import, disabling the WordPress file-type check. This allows high-privilege users, such as Administrators, to upload executable files. Immediate update of the plugin is recommended.
Azərbaycanca: Everest Toolkit WordPress plaginində (1.2.3 versiyasına qədər) demo məzmun idxalı zamanı yüklənən faylların tipi yoxlanılmır. Bu zəiflik yüksək səlahiyyətli istifadəçilərə (məsələn, administratorlar) icra olunan fayllar yükləməyə imkan verir. Plagini dərhal son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
Which users can exploit the CVE-2026-13158 vulnerability in the Everest Toolkit plugin?
This vulnerability allows high-privilege users, such as Administrators, to upload executable files.
What is recommended to protect against CVE-2026-13158?
Immediate update of the Everest Toolkit plugin is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.