Junglewise Threat Intelligence

CVE-2026-4357: WordPress Embed HTML5 Game plugin unauthenticated file upload

CVE-2026-4357 · Severity: critical · CVSS 10 · Published 2026-09-02

Vendors: Wordpress.

Executive brief

The Embed HTML5 Game WordPress plugin allows unauthenticated users to upload files without proper validation, enabling attackers to deploy malicious PHP code on vulnerable websites. This vulnerability allows remote attackers to gain unauthorized access and control over affected WordPress installations without requiring valid credentials or user interaction.

Technical details

The plugin fails to implement proper authentication and file type validation on its upload functionality. Unauthenticated attackers can exploit the upload mechanism to submit arbitrary files, including PHP backdoors, which can then be executed on the server. The vulnerability requires only network access to the affected WordPress site and no authentication credentials. Successful exploitation grants an attacker remote code execution capabilities, allowing complete compromise of the website. No known patch is currently available for affected versions through 1.3.

Affected products

  • WordPress Embed HTML5 Game through 1.3

Timeline

  • 2026-04-21: disclosed
  • 2026-09-02: advisory

References