Skip to content
Critical RCE Vulnerabilities in WordPress Plugins Exposed

Critical RCE Vulnerabilities in WordPress Plugins Exposed

First seen 11 Apr 2026, 09:09 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster April 12, 2026 at 01:03 UTC
  • CVE-2023-6553 allows RCE via LFI in Backup Migration plugin (CVSS 9.8).
  • CVE-2026-1830 enables RCE through unauthorized REST API access in Quick Playground plugin.
  • Immediate updates are recommended to mitigate these critical vulnerabilities.

Two critical vulnerabilities affecting WordPress plugins have been reported. CVE-2023-6553 targets the Backup Migration plugin (versions ≤1.3.7), allowing unauthenticated remote code execution through a Local File Inclusion flaw. The CVSS score for this vulnerability is 9.8, indicating its severity. The second vulnerability, CVE-2026-1830, affects the Quick Playground plugin (versions ≤1.3.1), enabling unauthenticated attackers to exploit insufficient authorization checks on REST API endpoints, leading to arbitrary file uploads and remote code execution. Both vulnerabilities pose significant risks, including full site takeover and data exfiltration. Security patches have been released for both plugins, urging users to update immediately. The vulnerabilities highlight the importance of proper input validation and access controls in plugin development.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 152d ago How this analysis works

Timeline

2023-12-01
CVE-2023-6553 discovered by NEX Team
2026-04-09
CVE-2026-1830 published
2026-04-10
Patches released for both vulnerabilities

More articles in this cluster (9)

Following this threat?

Track CVE-2026-1830 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed