← WordPress Vulnerabilities
WordPress security by component

Demo Import

Demo Import is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.

Plugin slug: demo-import

CVE-2026-13157: Demo Import lets multisite Administrators upload executable PHP files

Demo Import through 1.1.3 disables WordPress's file-type validation during demo-content import. A user with the import capability, Administrator by default, can upload an executable PHP file into the uploads directory. On multisite this lets a non-super subsite Administrator place server-side code beyond the privileges normally granted by the network. The record does not disclose the import endpoint, upload parameter, capability check, destination path or whether the web server executes PHP from uploads.

PublishedAug 01, 2026
Safe version guidanceSee mitigation notes
Safe version
Aug 01, 2026 CVE-2026-13157
Demo Import lets multisite Administrators upload executable PHP files
Demo Import through 1.1.3 disables WordPress's file-type validation during demo-content import. A user with the import capability, Administrator by default, can upload an executable PHP file into the uploads directory. On multisite this lets a non-super subsite Administrator place server-side code beyond the privileges normally granted by the network. The record does not disclose the import endpoint, upload parameter, capability check, destination path or whether the web server executes PHP from uploads.
See mitigation notes
CVEPending
NVDPending