PT-2026-31577 · WordPress · Quick Playground

Athiwat Tiprasaharn

+3

·

Published

2026-04-09

·

Updated

2026-05-30

·

CVE-2026-1830

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Quick Playground plugin for WordPress versions up to and including 1.3.1
Description The Quick Playground plugin for WordPress is susceptible to Remote Code Execution due to inadequate authorization checks on REST API endpoints. These endpoints expose a sync code and permit arbitrary file uploads. This allows unauthenticated attackers to retrieve the sync code, upload PHP files using path traversal techniques, and ultimately achieve remote code execution on the server.
Recommendations Update the Quick Playground plugin to a version later than 1.3.1.

Exploit

Fix

RCE

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-1830

Affected Products

Quick Playground