CVE-2026-1830Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization checks on REST API endpoints that expose a sync code and allow arbitrary file uploads. This makes it possible for unauthenticated attackers to retrieve the sync code, upload PHP files with path traversal, and achieve remote code execution on the server.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • Peaked 3d ago at 5 mentions (2026-04-09); latest day: 1
  • 8 total mentions across 4 days

Deep dive

Activity timeline8 mentions / 4d
01345Mentions · 2026-04-09: 5Mentions · 2026-04-10: 1Mentions · 2026-04-19: 1Mentions · 2026-07-28: 1PoC Mentioned / Linked · 2026-04-09: 1PoC Mentioned / Linked · 2026-04-19: 1Patch / Workaround · 2026-04-09: 1Technical Details · 2026-04-09: 5Technical Details · 2026-07-28: 104-0904-1004-1907-28
Signal classification3 categories
Disclosure
675.0%
Patch
112.5%
PoC
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-095
Disclosure4Patch1
2026-04-101
Disclosure1
2026-04-191
PoC1
2026-07-281
Disclosure1
Full discourse8 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-1830 - critical 🚨 Quick Playground <= 1.3.1 - Missing Authorization to Unauthenticated Arbitrary File Upload > The Quick Playground plugin for WordPress is vulnerable to remote code execution in a... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-1830 @pdn...

    Post summary

    The post announces CVE-2026-1830 in the Quick Playground WordPress plugin, describing a missing authorization flaw that allows arbitrary file upload and remote code execution, but provides no PoC, exploit code, or patch details.

    00011265
    1.1K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-1830 — CVSS 9.8/10 ██████████ The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including,... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/tXlhIsPj2R

    Post summary

    The tweet alerts to CVE-2026-1830, a critical RCE vulnerability in the Quick Playground WordPress plugin, and urges users to apply a patch immediately.

    1000042
    16 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-1830-quick-playground-version-1-3-1-critical-vulnerability-proof-of-concept CVE-2026-1830 #WordPress plugin #vulnerability quick-playground #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    A proof‑of‑concept for CVE-2026-1830 is linked and mentioned, but no actual exploit code, active exploitation, or patch information is provided.

    0000062
    6 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-1830 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-1830 #CVE-2026-1830 #CVE #Critical #Wordpress #CyberSecurity #InfoSec https://t.co/ZL3bF1bGTn

    Post summary

    The tweet announces the new CVE-2026-1830 with high severity, targeting WordPress, but provides no technical depth, PoC, or mitigation details.

    0000034
    123 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-1830: CRITICAL] Critical vulnerability in the Quick Playground WordPress plugin (up to v1.3.1) allows Remote Code Execution. Unauthenticated attackers can exploit REST API endpoints for malicious act...#cve,CVE-2026-1830,#cybersecurity https://cvefind.com/CVE-2026-1830

    Post summary

    A critical remote code execution vulnerability (CVE-2026-1830) in the Quick Playground WordPress plugin (up to v1.3.1) allows unauthenticated attackers to exploit REST API endpoints.

    0000068
    619 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-1830 The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization … https://www.cve.org/CVERecord?id=CVE-2026-1830 ----- Traducción: CVE-2026-1830 El … http://infoflow.cloud`

    Post summary

    The message announces CVE-2026-1830, describing it as a remote code execution vulnerability in the Quick Playground WordPress plugin, without providing a PoC, exploit, active attack evidence, or a patch.

    0000030
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1830 The Quick Playground plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.1. This is due to insufficient authorization … https://www.cve.org/CVERecord?id=CVE-2026-1830

    Post summary

    The Quick Playground WordPress plugin suffers from a remote code execution vulnerability (CVE‑2026‑1830) in all versions up to 1.3.1 due to insufficient authorization.

    00000256
    57.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-1830: Quic... WordPress plugin drops the ball on REST API auth - unauthenticated file upload + path traversal = instant RCE with CVSS 9.8 #WordPressSec #RCE #0day. https://zerodaysignal.com/vulnerability/CVE-2026-1830 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-1830, highlighting an unauthenticated file upload and path traversal flaw in a WordPress plugin that allows remote code execution, scoring CVSS 9.8, and provides a link to more details.

    00000115
    204 followersView on X

Explore more