Executive brief
The Quick Playground plugin for WordPress, which is used to create testing environments, contains a security flaw that allows unauthorized individuals to access sensitive server files. By exploiting this vulnerability, an attacker can download critical configuration files that may contain database credentials and other private site information. This could lead to a full site takeover or the exposure of sensitive customer data.
Technical details
A path traversal vulnerability exists in the qckply_zip_theme() function of the Quick Playground plugin for WordPress. The issue stems from insufficient validation of the 'stylesheet' parameter, which is appended directly to the theme root directory path without sanitizing directory traversal sequences (e.g., '../'). An unauthenticated remote attacker can exploit this to include arbitrary files from the server's filesystem into a ZIP archive. This can result in the disclosure of sensitive information, including the wp-config.php file which contains database credentials and security keys. The vulnerability is present in versions up to and including 1.3.3.
Affected products
- Quick Playground Quick Playground up to and including 1.3.3
Timeline
- 2026-05-15: disclosed: CVE published to the NVD dataset
References
- https://plugins.trac.wordpress.org/browser/quick-playground/tags/1.3.1/api.php
- https://plugins.trac.wordpress.org/browser/quick-playground/tags/1.3.1/api.php
- https://plugins.trac.wordpress.org/browser/quick-playground/tags/1.3.1/utility.php
- https://plugins.trac.wordpress.org/browser/quick-playground/tags/1.3.1/utility.php
- https://plugins.trac.wordpress.org/browser/quick-playground/trunk/api.php
- https://plugins.trac.wordpress.org/browser/quick-playground/trunk/api.php
- https://plugins.trac.wordpress.org/browser/quick-playground/trunk/utility.php