WordPress security by component
Everest Toolkit
Plugin description
Everest Toolkit is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.
Plugin slug:
everest-toolkitLatest vulnerability
CVE-2026-13158: Everest Toolkit demo imports let multisite Administrators upload PHP
Everest Toolkit through 1.2.3 disables WordPress's file-type test during demo-content import. A user with the import capability, Administrator by default, can upload an executable PHP file into the uploads directory. This crosses an important boundary on multisite because a subsite Administrator who is not a network Super Admin can place server-executable code. The record does not disclose the import endpoint, upload parameter, capability check, destination path or whether web-server PHP execution in uploads is required.
| Safe version |
|
||
|---|---|---|---|
| Aug 01, 2026 |
CVE-2026-13158
Everest Toolkit demo imports let multisite Administrators upload PHP
Everest Toolkit through 1.2.3 disables WordPress's file-type test during demo-content import. A user with the import capability, Administrator by default, can upload an executable PHP file into the uploads directory. This crosses an important boundary on multisite because a subsite Administrator who is not a network Super Admin can place server-executable code. The record does not disclose the import endpoint, upload parameter, capability check, destination path or whether web-server PHP execution in uploads is required.
|
See mitigation notes |
CVEPending
NVDPending
|