Sceawere

Vulnerability Detail

CVE-2026-104763UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Post Export Import Directory Traversal

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.9
Creation Date
2h ago
Vendor
wpazleen
Product
Post Export Import with Media
Attack Type
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Post Export Import with Media plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.17.1 via the 'file_path' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. This requires the attacker to upload a crafted ZIP archive containing a media_metadata.json file with path traversal sequences in the file_path field while specifying an allowed file extension for the destination filename to bypass the extension guard introduced in version 1.13.2.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.9",
  "pubDate": "2026-10-10T06:16:39.857Z",
  "pubdate": "2026-10-10T06:16:39.857Z",
  "executiveSummary": "The Post Export Import with Media WordPress plugin is susceptible to an authenticated arbitrary file read vulnerability via directory traversal.\nThe flaw exists in versions up to and including 1.17.1, enabling attackers with administrative privileges to read sensitive files on the host server.\nSuccessful exploitation requires the malicious actor to upload a specifically crafted ZIP archive containing a manipulated media_metadata.json file.\nThis vulnerability bypasses existing security controls by leveraging path traversal sequences within the file_path parameter, effectively neutralizing destination filename extension safeguards implemented in version 1.13.2.\nThe risk is significant as it grants elevated users unauthorized access to configuration files, credentials, or system data, potentially leading to full site compromise if sensitive secrets are exposed.",
  "technicalDetails": "The vulnerability originates from insufficient input sanitization of the 'file_path' parameter within the media import functionality of the Post Export Import with Media plugin. Despite previous attempts to restrict file handling in version 1.13.2, the logic fails to adequately validate or restrict paths provided within the 'media_metadata.json' file contained inside an imported ZIP archive.\nTo exploit this, an attacker with administrator-level access must initiate the import process by uploading a malicious ZIP archive. The attacker crafts a 'media_metadata.json' file where the 'file_path' field contains path traversal sequences (e.g., ../../../etc/passwd). By specifying an allowed file extension for the destination filename, the attacker maneuvers around the extension guard intended to prevent the manipulation of sensitive system files.\nThe attack flow proceeds as follows: First, the attacker uploads the weaponized ZIP archive through the plugin's administrative interface. Second, the plugin processes the 'media_metadata.json' file, extracting the 'file_path' field without adequate canonicalization or path validation. Third, the plugin's underlying file handling functions utilize this path, allowing the attacker to reference locations outside the intended media directory. Finally, the server reads the contents of the target file, which may then be processed or returned depending on the plugin's specific response handling.\nThis flaw is particularly dangerous because it grants authenticated attackers the ability to bypass directory restrictions. Even with the security measures added in version 1.13.2, the logical flaw in how 'file_path' is parsed allows for arbitrary path traversal. The impact of this vulnerability is high, as it facilitates the exfiltration of sensitive configuration files (such as wp-config.php), which often contain database credentials, secret keys, and other critical infrastructure details. Given the requirement for administrative privileges, this vulnerability is a prime target for lateral movement once a low-privileged administrator account has been compromised, or as an escalation path for authorized administrators performing malicious activities."
}
CVE-2026-104763: Post Export Import Directory Traversal (MEDIUM Severity, CVSS: 4.9) | Sceawere