PT-2026-67025 · WordPress · Everest Toolkit

CVE-2026-13158

·

Published

2026-08-01

·

Updated

2026-08-05

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Everest Toolkit versions prior to 1.2.4
Description Insufficient validation of uploaded file types occurs during the demo-content import process because the WordPress file-type test is disabled. This allows high-privilege users, such as Administrators and non-super-admin site administrators on multisite installations, to upload executable PHP files to the uploads directory.
Recommendations Update Everest Toolkit to version 1.2.4 or later.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13158

Affected Products

Everest Toolkit