Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 04 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 03 Aug 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-434 |
Mon, 03 Aug 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file into a public directory, resulting in remote code execution on servers configured to execute it. | |
| Title | Insert or Embed Articulate Content into WordPress <= 4.3000000027 - Editor+ Arbitrary File Upload | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-04T18:02:30.186Z
Reserved: 2026-07-17T12:16:09.173Z
Link: CVE-2026-16060
Updated: 2026-08-04T18:02:13.239Z
Status : Received
Published: 2026-08-03T07:16:40.633
Modified: 2026-08-04T19:16:42.807
Link: CVE-2026-16060
No data.
OpenCVE Enrichment
Updated: 2026-08-04T21:45:04Z