WordPress Plugin Vulnerabilities

Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File Upload

Description

The plugin does not validate the type of files uploaded during demo-content import (the WordPress file-type test is disabled), allowing high-privilege users (Administrator by default, including non-super-admin site administrators on multisite) to upload executable PHP files to the uploads directory.

Proof of Concept

Affects Plugins

No known fix

References

Miscellaneous

Original Researcher
Huynh Kien Minh
Submitter
Huynh Kien Minh
Verified
Yes

Timeline

Publicly Published
2026-07-17 (about 16 days ago)
Added
2026-07-10 (about 23 days ago)
Last Updated
2026-07-10 (about 23 days ago)

Other