plugin

Post Export Import With Media Vulnerabilities

1 known security issue reported for the Post Export Import With Media WordPress plugin. Most recent disclosed Jul 9, 2026.

1 high

Running Post Export Import With Media on your site? Check whether your installed version is affected.

Scan your site free

Post Export Import with Media <= 1.13.1 - Authenticated (Administrator+) Arbitrary File Upload via Trailing-Dot Filename Bypass in ZIP Media Import

high

The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.13.1 via the import_media_file_secure function. This is due to insufficient file extension validation caused by a trailing-dot filename bypass, where the extension allow-list check in aj...

CVSS:
7.2
Affected:
up to 1.13.1
Fixed in:
1.13.2
Disclosed:
Jul 9, 2026

CVE-2026-13430 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database