CVE-2026-16060 PUBLISHED

Insert or Embed Articulate Content into WordPress <= 4.3000000027 - Editor+ Arbitrary File Upload

Assigner: WPScan
Reserved: 17.07.2026 Published: 03.08.2026 Updated: 03.08.2026

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file into a public directory, resulting in remote code execution on servers configured to execute it.

Product Status

Vendor Unknown
Product Insert or Embed Articulate Content into WordPress
Versions Default: unknown
  • affected from 0 to 4.3000000027 (incl.)

Credits

  • Yaswanth Reddy Sunkara finder
  • WPScan coordinator

References

Problem Types

  • CWE-434 Unrestricted Upload of File with Dangerous Type CWE