Critical RCE Vulnerabilities in WordPress Plugins Exposed

Critical RCE Vulnerabilities in WordPress Plugins Exposed

First seen 11 Apr 2026, 09:09 UTC MediumSentineloneBleepingcomputerScworldSecurityaffairs.Co+2 81% similarity 72.0

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities affecting WordPress plugins have been reported. CVE-2023-6553 targets the Backup Migration plugin (versions ≤1.3.7), allowing unauthenticated remote code execution through a Local File Inclusion flaw. The CVSS score for this vulnerability is 9.8, indicating its severity. The second vulnerability, CVE-2026-1830, affects the Quick Playground plugin (versions ≤1.3.1), enabling unauthenticated attackers to exploit insufficient authorization checks on REST API endpoints, leading to arbitrary file uploads and remote code execution. Both vulnerabilities pose significant risks, including full site takeover and data exfiltration. Security patches have been released for both plugins, urging users to update immediately. The vulnerabilities highlight the importance of proper input validation and access controls in plugin development.

Key Points: • CVE-2023-6553 allows RCE via LFI in Backup Migration plugin (CVSS 9.8). • CVE-2026-1830 enables RCE through unauthorized REST API access in Quick Playground plugin. • Immediate updates are recommended to mitigate these critical vulnerabilities.

ThreatCluster AI How this analysis works

Timeline

2023-12-01
CVE-2023-6553 discovered by NEX Team
2026-04-09
CVE-2026-1830 published
2026-04-10
Patches released for both vulnerabilities

Community

Browse all →

Tracked Entities in This Story