Critical Vulnerability in Embed HTML5 Game WordPress Plugin Allows Unauthenticated PHP Backdoor Uploads
A critical vulnerability, CVE-2026-4357, with a CVSS score of 10, was discovered in the Embed HTML5 Game WordPress plugin (version 1.3 and below). This vulnerability allows unauthenticated attackers to upload PHP backdoors on affected sites, potentially leading to remote code execution, data breaches, and site takeovers. Immediate patching or mitigation is essential to prevent exploitation. The vulnerability has not been actively exploited yet, but its severity and potential impact warrant urgent attention.