Junglewise Threat Intelligence

CVE-2026-13430: wpazleen Post Export Import with Media arbitrary file upload

CVE-2026-13430 · Severity: high · CVSS 7.2 · Published 2026-07-10

Executive brief

The Post Export Import with Media plugin for WordPress, which is used to manage and transfer website content, contains a security flaw that allows high-level users to upload malicious files. An attacker with administrator privileges could exploit this to upload executable scripts, potentially leading to a full takeover of the website and its underlying server. This could result in the theft of sensitive customer data or a complete service outage.

Technical details

The Post Export Import with Media plugin for WordPress is vulnerable to unrestricted file uploads due to a trailing-dot filename bypass in the ajax_import_media_start() function. The vulnerability occurs because pathinfo() is used on raw ZIP entry names (e.g., 'shell.php.'); when a trailing dot is present, it returns an empty string for the extension, causing the allow-list validation to be bypassed. The file is then extracted to a temporary location and subsequently moved to the WordPress uploads directory by import_media_file_secure() without further validation. An authenticated attacker with administrator-level privileges can exploit this to upload PHP files and achieve remote code execution (RCE). The issue is present in all versions up to and including 1.13.1.

Affected products

  • wpazleen Post Export Import with Media up to, and including, 1.13.1

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory

References