Executive brief
The Post Export Import with Media plugin for WordPress, which is used to manage and transfer website content, contains a security flaw that allows high-level users to upload malicious files. An attacker with administrator privileges could exploit this to upload executable scripts, potentially leading to a full takeover of the website and its underlying server. This could result in the theft of sensitive customer data or a complete service outage.
Technical details
The Post Export Import with Media plugin for WordPress is vulnerable to unrestricted file uploads due to a trailing-dot filename bypass in the ajax_import_media_start() function. The vulnerability occurs because pathinfo() is used on raw ZIP entry names (e.g., 'shell.php.'); when a trailing dot is present, it returns an empty string for the extension, causing the allow-list validation to be bypassed. The file is then extracted to a temporary location and subsequently moved to the WordPress uploads directory by import_media_file_secure() without further validation. An authenticated attacker with administrator-level privileges can exploit this to upload PHP files and achieve remote code execution (RCE). The issue is present in all versions up to and including 1.13.1.
Affected products
- wpazleen Post Export Import with Media up to, and including, 1.13.1
Timeline
- 2026-07-10: disclosed
- 2026-07-10: advisory
References
- https://plugins.trac.wordpress.org/browser/post-export-import-with-media/tags/1.13.1/includes/class-media-handler.php
- https://plugins.trac.wordpress.org/browser/post-export-import-with-media/tags/1.13.1/includes/class-media-handler.php
- https://plugins.trac.wordpress.org/browser/post-export-import-with-media/tags/1.13.1/includes/class-media-handler.php
- https://plugins.trac.wordpress.org/browser/post-export-import-with-media/tags/1.13.1/includes/class-media-handler.php
- https://plugins.trac.wordpress.org/browser/post-export-import-with-media/tags/1.13.1/includes/class-media-handler.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3600506%40post-export-import-with-media&new=3600506%40post-export-import-with-media
- https://www.wordfence.com/threat-intel/vulnerabilities/id/42f94f80-6157-4778-ad69-184943134fd2?source=cve