CyberRota
← Ana sayfaya dön

CVE-2026-13158

UNKNOWN · CVSS N/A

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-08-01T07:16:29.133 · Çekilme zamanı: 2026-08-01T12:06:04.669265+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-13158
Severity
UNKNOWN
CVSS
N/A
EPSS
Yok
WordPress

Orijinal NVD Açıklaması

The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the uploads directory.