Description
The Post Export Import with Media plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.17.1 via the 'file_path' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. This requires the attacker to upload a crafted ZIP archive containing a media_metadata.json file with path traversal sequences in the file_path field while specifying an allowed file extension for the destination filename to bypass the extension guard introduced in version 1.13.2.
Published: 2026-10-10
Score: 4.9 Medium
EPSS: n/a
KEV: No
Impact: Arbitrary File Read via Directory Traversal
Action: Patch
AI Analysis

Impact

The vulnerability in the WordPress Post Export Import with Media plugin allows authenticated attackers with administrator-level access to exploit a directory traversal flaw. By uploading a specially crafted ZIP archive that contains a media_metadata.json file with back‑door path traversal sequences in the 'file_path' field, an attacker can cause the plugin to read the contents of any file on the server. The flaw results in the disclosure of potentially sensitive data without requiring elevated system privileges, and the weakness is classified as CWE‑22.

Affected Systems

WordPress sites running the Post Export Import with Media plugin, versions up to and including 1.17.1, are affected. The issue is present in all builds before 1.18, and any site that has not yet upgraded beyond the 1.17.1 release remains vulnerable.

Risk and Exploitability

The CVSS score of 4.9 indicates moderate severity, and the EPSS score is not currently available, suggesting the exploitation probability is not well quantified. The attack requires a valid administrator account to upload the malicious ZIP, implying that ordinary users cannot exploit it. However, within the administrative role, the path traversal can be leveraged to read arbitrary files, thereby granting the attacker access to sensitive information. Because the flaw is tied to an authenticated context, the risk is concentrated in environments where administrative privileges are broadly granted or not tightly controlled; the plugin does not permit anonymous exploitation.

Generated by OpenCVE AI on October 10, 2026 at 06:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Post Export Import with Media plugin to the latest stable release (≥ 1.18) to remove the directory traversal flaw.
  • Configure the WordPress site to enforce strict path sanitization for file uploads, ensuring that any uploaded 'file_path' entries are validated or rejected if they contain traversal sequences.
  • Review and limit administrator privileges so that only trusted users can perform media import/export operations, reducing the attack surface for this flaw.

Generated by OpenCVE AI on October 10, 2026 at 06:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Post Export Import with Media plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.17.1 via the 'file_path' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. This requires the attacker to upload a crafted ZIP archive containing a media_metadata.json file with path traversal sequences in the file_path field while specifying an allowed file extension for the destination filename to bypass the extension guard introduced in version 1.13.2.
Title Post Export Import with Media <= 1.17.1 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'file_path' Parameter in media_metadata.json
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T05:30:59.595Z

Reserved: 2026-10-02T12:36:56.500Z

Link: CVE-2026-104763

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T06:16:39.857

Modified: 2026-10-10T06:16:39.857

Link: CVE-2026-104763

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T06:30:18Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')