Post Export Import with Media WordPress Plugin Arbitrary File Upload Vulnerability

Vulnerability

A vulnerability allowing arbitrary file upload has been identified in the Post Export Import with Media plugin for WordPress, affecting all versions through 1.13.1. The issue arises in the import_media_file_secure function, where inadequate validation of file extensions allows for the upload of potentially executable files. This vulnerability exploits a trailing-dot filename bypass, which interferes with the extension allow-list check. Authenticated attackers with administrator-level access can leverage this flaw to upload files that could be executed remotely.

Impact

Exploitation of this vulnerability could lead to unauthorized file uploads, with the potential for those files to be executed on the server, allowing for remote code execution.

Reproduction

To reproduce this vulnerability, an authenticated user with administrator privileges can upload a ZIP file containing a malicious PHP file. The trailing dot in the filename bypasses the plugin's extension checks, allowing the file to be extracted and subsequently imported into the WordPress uploads directory without proper validation. Once the file is in the uploads directory, it can be executed, leading to remote code execution.

Remediation

Users are advised to update the Post Export Import with Media plugin to version 1.13.2 or later, where this vulnerability has been patched.

Added: Jul 10, 2026, 4:31 AM
Updated: Jul 10, 2026, 4:31 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.8
remediation
0.0
relevance
9.3
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.