← Terug naar overzicht

CVE-2026-4357 affects the Embed HTML5 Game WordPress plugin through version 1.3. The plugin fails to properly restrict file upload functionality, both in terms of who can upload files and what file types are permitted. This critical flaw allows unauthenticated attackers to upload PHP backdoors to affected WordPress sites without any authentication. Successful exploitation could result in full remote code execution and complete site compromise. The vulnerability is particularly dangerous as it requires no credentials or privileges to exploit. WordPress site administrators using this plugin are urged to remove or update it immediately. The issue has been documented on both NVD and WPScan databases.

Affected products

  • Embed HTML5 Game WordPress Plugin 1.3

Related CVE's

  • CVE-2026-4357

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities