CVE-2026-16060
N/A
N/A
Summary
The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file into a public directory, resulting in remote code execution on servers configured to execute it.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Insert or Embed Articulate Content into WordPress | 0 <= 4.3000000027 | affected |
Weaknesses
- CWE-434 Unrestricted Upload of File with Dangerous Type
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.