Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-13430— Post Export Import with Media <= 1.13.1 - Authenticated (Administrator+) Arbitrary File Upload via Trailing-Dot Filename Bypass in ZIP Media Import

Quick assessment

Affected
wpazleen Post Export Import with Media
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress Post Export Import with Media是WordPress基金会的一款支持媒体文件导入导出的内容导出插件。 WordPress Post Export Import with Media 1.13.1及之前版本存在任意文件上传漏洞,该漏洞源于对import_media_file_secure函数中文件扩展名验证不足,通过尾部点文件名绕过,可能导致具有管理员权限及以上的认证攻击者上传可执行文件,从而实现远程代码执行。

CVSS 7.2 · High EPSS 1.15% · P66

Affected Version Matrix 1

VendorProduct Version RangeStatus
wpazleen Post Export Import with Media ≤ 1.13.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-13430

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Post Export Import with Media <= 1.13.1 - Authenticated (Administrator+) Arbitrary File Upload via Trailing-Dot Filename Bypass in ZIP Media Import
Source: CVE Program / CVE List V5
Vulnerability Description
The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.13.1 via the import_media_file_secure function. This is due to insufficient file extension validation caused by a trailing-dot filename bypass, where the extension allow-list check in ajax_import_media_start() uses pathinfo() on the raw ZIP entry name (e.g., 'shell.php.'), which returns an empty string for the extension, causing the allow-list guard to be skipped and the file to be extracted to a temporary location, after which import_media_file_secure() copies it into the WordPress uploads directory without re-validating the extension. This makes it possible for authenticated attackers, with administrator-level access and above, to upload files that may be executable, which makes remote code execution possible.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
危险类型文件的不加限制上传
Source: CVE Program / CVE List V5
Vulnerability Title
WordPress Post Export Import with Media 任意文件上传漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WordPress Post Export Import with Media是WordPress基金会的一款支持媒体文件导入导出的内容导出插件。 WordPress Post Export Import with Media 1.13.1及之前版本存在任意文件上传漏洞,该漏洞源于对import_media_file_secure函数中文件扩展名验证不足,通过尾部点文件名绕过,可能导致具有管理员权限及以上的认证攻击者上传可执行文件,从而实现远程代码执行。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
wpazleen Post Export Import with Media 0 ~ 1.13.1 -

II. Public POCs for CVE-2026-13430

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-13430

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-13430 (2)

Vendor Advisories for CVE-2026-13430 (1)

Vendor Pages for CVE-2026-13430 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-13430

No comments yet


Leave a comment