ZeroHour

CVE-2026-4357

Unauthenticated Arbitrary File Upload in Embed HTML5 Game WordPress Plugin

CVSS 3.1
10.0 critical
EPSS
<1%p23
Published
()
Modified
AI analysis

The Embed HTML5 Game WordPress plugin through version 1.3 fails to properly restrict who can upload files through the plugin and what file types are permitted, creating an unauthenticated unrestricted file upload flaw (CWE-434). An attacker can trigger the flaw by sending a crafted upload request to the plugin's upload functionality on a vulnerable WordPress site without any account or privileges. Because uploaded files are not type-restricted, the attacker can plant a PHP backdoor or web shell on the server and request it, achieving remote code execution with full impact on confidentiality, integrity, and availability. Any WordPress site running Embed HTML5 Game version 1.3 or earlier is affected. As of now there is no known public proof of concept, no entry in the CISA KEV catalog, and no confirmed exploitation in the wild, with EPSS estimating only a 0.3% probability of exploitation in the next 30 days.

What to do: Update the Embed HTML5 Game plugin to a version newer than 1.3 as soon as a patched release is available, or deactivate the plugin until an update can be applied. In the interim, block or restrict unauthenticated access to the plugin's upload endpoint and audit the site's uploads directories for unexpected PHP files that may indicate a backdoor was already planted. Given the critical (CVSS 10) severity, prioritize this check on all sites where the plugin is active.

Affected
Embed HTML5 Game (WordPress plugin) Embed HTML5 Gamethrough 1.3 (all versions up to and including 1.3)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites.

Ecosystems
WordPress
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.