Feed/CVE-2026-13158
CVE-2026-13158HIGHCVSS 7.2

CVE-2026-13158

Published Aug 1, 2026·Updated Aug 5, 2026

NVD Description

The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the uploads directory.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free