๐Ÿ” CVE Alert

CVE-2026-13158

UNKNOWN 0.0

Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the uploads directory.

Vendor unknown
Product everest toolkit
Published Aug 1, 2026
Stay Ahead of the Next One

Get instant alerts for unknown everest toolkit

Be the first to know when new unknown vulnerabilities affecting unknown everest toolkit are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Everest Toolkit
0 โ‰ค 1.2.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/f101071f-402a-40a2-bbdb-666512cd4049/

Credits

Huynh Kien Minh WPScan