CyberRota Analysis
AI-GeneratedThe Embed HTML5 Game WordPress plugin versions up to 1.3 is vulnerable due to inadequate restrictions on file uploads, allowing unauthenticated attackers to upload malicious PHP backdoors. This critical vulnerability poses a severe risk of unauthorized access and potential site compromise. WordPress site administrators using this plugin should prioritize immediate updates or mitigation measures to safeguard against exploitation.
Original NVD Description
The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites.