SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-13158

HIGH · CVSS 7.2 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-08-01 · Last synced 2026-08-31

CyberRota Analysis

AI-Generated

The Everest Toolkit WordPress plugin versions up to 1.2.3 are vulnerable due to inadequate validation of file types during demo-content import, allowing high-privilege users, including non-super-admin site administrators on multisite installations, to upload executable PHP files to the uploads directory. This flaw can lead to remote code execution, potentially compromising the entire WordPress site. WordPress administrators and security teams should prioritize addressing this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-13158
Severity
HIGH
CVSS
7.2
EPSS
0.35%
WordPress

Original NVD Description

The Everest Toolkit WordPress plugin through 1.2.3 does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the uploads directory.