Quick Playground <= 1.3.4 - Authenticated (Administrator+) Arbitrary File Read via 'filename' Parameter
medium
The Quick Playground plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.4. This is due to the `qckply_data()` function passing the user-supplied `filename` POST parameter directly to `file_get_contents()` without any validation, sanitization, or path restriction. This makes i...
- CVSS:
- 4.4
- Affected:
- up to 1.3.4
- Fixed in:
- 1.3.5
- Disclosed:
- Jun 5, 2026
CVE-2026-2500 on NVD →
Quick Playground <= 1.3.3 - Unauthenticated Path Traversal to Arbitrary File Read via 'stylesheet' Parameter
high
The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is due to insufficient path validation in the qckply_zip_theme() function, which appends a user-controlled 'stylesheet' parameter directly to the theme root directory path without sanitizing directory t...
- CVSS:
- 7.5
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.4
- Disclosed:
- May 14, 2026
CVE-2026-6403 on NVD →
Quick Playground <= 1.3.1 - Missing Authorization to Unauthenticated Arbitrary File Upload
critical
The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization checks on REST API endpoints that expose a sync code and allow arbitrary file uploads. This makes it possible for unauthenticated attackers to retrieve...
- CVSS:
- 9.8
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.2
- Disclosed:
- Apr 8, 2026
CVE-2026-1830 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database