CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-1830 — The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution...

·Source: NIST NVD

Updated:

Executive Summary

The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization checks on REST API endpoints that expose a sync code and allow arbitrary file uploads. This makes it possible for unauthenticated attackers to retrieve the sync code, upload PHP files with path traversal, and achieve remote code exe

Analysis

The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization checks on REST API endpoints that expose a sync code and allow arbitrary file uploads. This makes it possible for unauthenticated attackers to retrieve the sync code, upload PHP files with path traversal, and achieve remote code execution on the server. CVSS Score: 9.8. Published: 2026-04-09T05:16:03.420.

Indicators of Compromise (1)

CVE (1)
CVE-2026-1830
Source Attribution

Originally published by NIST NVD on Apr 9, 2026. Verified by: NIST.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-102240 — A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the ...

A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/network_tools of the component Network Tools CGI. The manipulation of the argument sid results in os command injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not res

CVE-2026-102240
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101354 — A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affecte...

A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affected element is the function _tWlanTask of the component MmtAtePrase Parser. Performing a manipulation results in stack-based buffer overflow. The attacker must have access to the local network to execute the attack. The exploit has been released to the public and may be used for attacks. The vendor was contacted early ab

CVE-2026-101354
NIST NVD
MEDIUMAi

Nvidia releases Open Agent Safety Platform to monitor and govern agentic AI

Nvidia on Monday rolled out an agentic governance system called the Open Agent Safety Platform that combines software with out-of-band DPU-based silicon in a reference system design that it says will secure agents “from testing to deployment.” But while the Nvidia design’s silicon-based component provides some cybersecurity advantages, analysts argued that it cannot help with the vast majority of

CSO Online