/Vulnerability Library

Quick Playground <= 1.3.1 - Missing Authorization to Unauthenticated Arbitrary File Upload

CVE-2026-1830
Verified

Description

The Quick Playground plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 1.3.1. The plugin exposes a blueprint REST API endpoint (permission_callback: __return_true) that leaks the sync code, and an upload_image endpoint that accepts file uploads with path traversal in the filename parameter without sufficient authorization checks, which can be chained into arbitrary PHP file upload and RCE.

Severity

Critical

CVSS Score

9.8

Exploit Probability

8%

Affected Product

quick-playground

Published Date

July 23, 2026

Template Author

iamatownboy

CVE-2026-1830.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-1830
CWE ID:
cwe-862

References

https://nvd.nist.gov/vuln/detail/CVE-2026-1830https://www.wordfence.com/threat-intel/vulnerabilities/id/308cd28a-a477-4bc6-a392-ad5a9eca1cb5?source=cvehttps://plugins.trac.wordpress.org/browser/quick-playground/trunk/api.php#L39https://plugins.trac.wordpress.org/browser/quick-playground/trunk/expro-api.php#L419https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3500839%40quick-playground&new=3500839%40quick-playground&sfp_email=&sfph_mail=

Remediation Steps

Update Quick Playground to version 1.3.2 or later.