CVE-2026-13158 is an improper file upload validation vulnerability in the Everest Toolkit WordPress plugin through version 1.2.3. During the demo-content import workflow, the plugin disables the normal WordPress file-type test and fails to validate the type of uploaded files. As a result, a high-privilege authenticated user can upload executable PHP content into the WordPress uploads directory. In default configurations this affects Administrator users, and on multisite deployments it also affects non-super-admin site administrators by default. Because the uploaded file can be server-executable PHP, successful exploitation can lead to arbitrary code execution in the context of the web server and the affected WordPress instance.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is not a source-code exploit project but a documentation-heavy advisory/PoC write-up for CVE-2026-13158 affecting the Everest Toolkit WordPress plugin <= 1.2.3. The repo contains 6 files: license/policy documents plus three rendered write-up formats (README.md, writeup_cve_2026_13158.md, and two HTML renderings). There is no standalone executable exploit file in the repository; instead, the exploit logic is embedded as code snippets inside the markdown/html documentation. The described exploit is an authenticated web attack: an Admin+ user logs into WordPress, sends a multipart POST to /wp-admin/admin-ajax.php with an action value intended to reach the plugin’s upload handler, uploads a PHP payload, and then accesses the returned file_url with a cmd parameter to execute OS commands. The payload is a basic PHP web shell using system()/passthru() and optional host-information output. This makes the exploit operational rather than just theoretical, though it is still a PoC with hardcoded credentials/URLs. Notable inconsistency: the repository contains multiple variants of the vulnerable handler and action names. One write-up references add_action('wp_ajax_everest_toolkit_import_file', ...) with uploaded field import_file, while the README PoC uses action=everest_toolkit_file_upload and field toolkit_import_file. This suggests the repository is primarily an advisory narrative rather than a rigorously validated exploit package. Still, the core capability is clear: arbitrary PHP upload to a web-accessible WordPress uploads directory leading to RCE. Overall purpose: publish a vulnerability advisory, explain root cause, provide example vulnerable code patterns, and include embedded PoC snippets for authenticated arbitrary file upload to RCE in a WordPress plugin context.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.