PT-2026-84724 · WordPress · Embed Html5 Game

·

CVE-2026-4357

·

Published

2026-09-02

·

Updated

2026-09-04

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Embed HTML5 Game WordPress plugin versions prior to 1.4
Description The plugin fails to properly restrict file upload permissions and the types of files that can be uploaded. This allows unauthenticated attackers to upload arbitrary files, such as PHP backdoors, to the affected sites.
Recommendations Update the plugin to a version newer than 1.3. Remove the plugin if it is no longer needed.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4357

Affected Products

Embed Html5 Game