Feed/CVE-2026-16060
CVE-2026-16060CRITICALCVSS 9.8

CVE-2026-16060

Published Aug 3, 2026·Updated Aug 4, 2026

NVD Description

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file into a public directory, resulting in remote code execution on servers configured to execute it.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free