Executive brief
The Embed HTML5 Game WordPress plugin allows unauthenticated users to upload files without proper validation, enabling attackers to deploy malicious PHP code on vulnerable websites. This vulnerability allows remote attackers to gain unauthorized access and control over affected WordPress installations without requiring valid credentials or user interaction.
Technical details
The plugin fails to implement proper authentication and file type validation on its upload functionality. Unauthenticated attackers can exploit the upload mechanism to submit arbitrary files, including PHP backdoors, which can then be executed on the server. The vulnerability requires only network access to the affected WordPress site and no authentication credentials. Successful exploitation grants an attacker remote code execution capabilities, allowing complete compromise of the website. No known patch is currently available for affected versions through 1.3.
Affected products
- WordPress Embed HTML5 Game through 1.3
Timeline
- 2026-04-21: disclosed
- 2026-09-02: advisory