SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-4357

CRITICAL · CVSS 10 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Embed HTML5 Game WordPress plugin versions up to 1.3 is vulnerable due to inadequate restrictions on file uploads, allowing unauthenticated attackers to upload malicious PHP backdoors. This critical vulnerability poses a severe risk of unauthorized access and potential site compromise. WordPress site administrators using this plugin should prioritize immediate updates or mitigation measures to safeguard against exploitation.

CVE
CVE-2026-4357
Severity
CRITICAL
CVSS
10
EPSS
0.30%
WordPress

Original NVD Description

The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites.