9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization checks on REST API endpoints that expose a sync code and allow arbitrary file uploads. This makes it possible for unauthenticated attackers to retrieve the sync code, upload PHP files with path traversal, and achieve remote code execution on the server.
Basic Information
ID
CVE-2026-1830
Source
Wordfence
Published
Apr 9, 2026 at 03:25
Modified
Apr 9, 2026 at 13:34
Affected Product
Vendor
davidfcarr
Product
Quick Playground
Affected Versions
davidfcarr Quick Playground 0