CVE-2026-13158
Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the uploads directory.
| Vendor | unknown |
| Product | everest toolkit |
| Published | Aug 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown everest toolkit
Be the first to know when new unknown vulnerabilities affecting unknown everest toolkit are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Everest Toolkit
0 โค 1.2.3
References
Credits
Huynh Kien Minh WPScan