Impact
The Embed HTML5 Game WordPress plugin through version 1.3 fails to restrict file uploads or enforce file type validation. This allows an unauthenticated user to upload PHP files to the site, effectively giving the attacker a backdoor that can be executed as server code. The weakness is a classic improperly validated input flaw (CWE-434).
Affected Systems
Any WordPress installation running Embed HTML5 Game version 1.3 or earlier is susceptible. The vulnerability applies to all users of the plugin regardless of role because there is no authentication or permission check for uploads.
Risk and Exploitability
The CVSS score of 10 classifies this as a critical issue, and the lack of an authentication barrier means any visitor can perpetrate the upload. Although EPSS data is unavailable, the ease of exploitation and the immediate remote code execution potential make the threat high. The vulnerability is not yet listed as a known exploited vulnerability in the CISA KEV catalog, but the severity warrants urgent attention.
OpenCVE Enrichment