PT-2026-84724 · WordPress · Embed Html5 Game
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Embed HTML5 Game WordPress plugin versions prior to 1.4
Description
The plugin fails to properly restrict file upload permissions and the types of files that can be uploaded. This allows unauthenticated attackers to upload arbitrary files, such as PHP backdoors, to the affected sites.
Recommendations
Update the plugin to a version newer than 1.3.
Remove the plugin if it is no longer needed.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Embed Html5 Game