CRITICAL 10 CVE-2026-4357 Published 2 Sept 2026

WordPress Embed HTML5 Game Plugin Unauthenticated File Upload

Worried this affects one of your servers?

The Embed HTML5 Game WordPress plugin, up to version 1.3, has a vulnerability that allows unauthenticated attackers to upload PHP backdoors to affected sites.

Impact: Successful exploitation could result in remote code execution (RCE) on the affected website.

Affected Product: WordPress Embed HTML5 Game plugin, versions up to 1.3.

Reference: CVE-2026-4357 on NVD

← Back to Security News