CVE-2026-13157
Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File Upload
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Demo Import WordPress plugin through 1.1.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the uploads directory.
| Vendor | unknown |
| Product | theme demo import |
| Published | Aug 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown theme demo import
Be the first to know when new unknown vulnerabilities affecting unknown theme demo import are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Theme Demo Import
0 โค 1.1.3
References
Credits
Huynh Kien Minh WPScan