๐Ÿ” CVE Alert

CVE-2026-13157

UNKNOWN 0.0

Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File Upload

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the uploads directory.

Vendor unknown
Product theme demo import
Published Aug 1, 2026
Stay Ahead of the Next One

Get instant alerts for unknown theme demo import

Be the first to know when new unknown vulnerabilities affecting unknown theme demo import are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Theme Demo Import
0 โ‰ค 1.1.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/5d6a6a8e-c224-4034-8ed5-2d63f37f9479/

Credits

Huynh Kien Minh WPScan