PoC Index82,564 CVEs with PoCs

CVE-2026-4357

Embed HTML5 Game <= 1.3 - Unauthenticated Arbitrary File Upload

CRITICAL 10.0EPSS 0.3%

The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites.

Affected
Embed HTML5 Game
CVSS v3.1 WPSCAN
10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS
0.30% chance of exploitation in the next 30 days, 23rd percentile
Published
2026-09-02

Proof-of-concept exploits (1)

References