CRITICAL
10 CVE-2026-4357 Published 2 Sept 2026
WordPress Embed HTML5 Game Plugin Unauthenticated File Upload
Worried this affects one of your servers?
The Embed HTML5 Game WordPress plugin, up to version 1.3, has a vulnerability that allows unauthenticated attackers to upload PHP backdoors to affected sites.
Impact: Successful exploitation could result in remote code execution (RCE) on the affected website.
Affected Product: WordPress Embed HTML5 Game plugin, versions up to 1.3.
Reference: CVE-2026-4357 on NVD
← Back to Security News