WordPress security by component
Demo Import
Plugin description
Demo Import is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.
Plugin slug:
demo-importLatest vulnerability
CVE-2026-13157: Demo Import lets multisite Administrators upload executable PHP files
Demo Import through 1.1.3 disables WordPress's file-type validation during demo-content import. A user with the import capability, Administrator by default, can upload an executable PHP file into the uploads directory. On multisite this lets a non-super subsite Administrator place server-side code beyond the privileges normally granted by the network. The record does not disclose the import endpoint, upload parameter, capability check, destination path or whether the web server executes PHP from uploads.
| Safe version |
|
||
|---|---|---|---|
| Aug 01, 2026 |
CVE-2026-13157
Demo Import lets multisite Administrators upload executable PHP files
Demo Import through 1.1.3 disables WordPress's file-type validation during demo-content import. A user with the import capability, Administrator by default, can upload an executable PHP file into the uploads directory. On multisite this lets a non-super subsite Administrator place server-side code beyond the privileges normally granted by the network. The record does not disclose the import endpoint, upload parameter, capability check, destination path or whether the web server executes PHP from uploads.
|
See mitigation notes |
CVEPending
NVDPending
|