CVE 9.8 CRITICAL

Quick Playground <= 1.3.1 - Missing Authorization to Unauthenticated Arbitrary File Upload_CVE-2026-1830

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization checks on REST API endpoints that expose a sync code and allow arbitrary file uploads. This makes it possible for unauthenticated attackers to retrieve the sync code, upload PHP files with path traversal, and achieve remote code execution on the server.

Basic Information

ID CVE-2026-1830
Source Wordfence
Published Apr 9, 2026 at 03:25
Modified Apr 9, 2026 at 13:34

Affected Product

Vendor davidfcarr
Product Quick Playground
Affected Versions davidfcarr Quick Playground 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.