Quick Playground <= 1.3.1 - Missing Authorization to Unauthenticated Arbitrary File Upload
CVE-2026-1830
Verified
Description
The Quick Playground plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 1.3.1. The plugin exposes a blueprint REST API endpoint (permission_callback: __return_true) that leaks the sync code, and an upload_image endpoint that accepts file uploads with path traversal in the filename parameter without sufficient authorization checks, which can be chained into arbitrary PHP file upload and RCE.
Severity
Critical
CVSS Score
9.8
Exploit Probability
8%
Affected Product
quick-playground
Published Date
July 23, 2026
Template Author
iamatownboy
CVE-2026-1830.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-1830
CWE ID:
cwe-862
References
https://nvd.nist.gov/vuln/detail/CVE-2026-1830https://www.wordfence.com/threat-intel/vulnerabilities/id/308cd28a-a477-4bc6-a392-ad5a9eca1cb5?source=cvehttps://plugins.trac.wordpress.org/browser/quick-playground/trunk/api.php#L39https://plugins.trac.wordpress.org/browser/quick-playground/trunk/expro-api.php#L419https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3500839%40quick-playground&new=3500839%40quick-playground&sfp_email=&sfph_mail=
Remediation Steps
Update Quick Playground to version 1.3.2 or later.