Extension WordPress

Vulnérabilités Quick Playground

Cette page rassemble les failles publiées pour Quick Playground, leurs plages de versions affectées et les correctifs signalés dans la base locale.

3Vulnérabilités
1Critiques
3Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Quick Playground

3 fiches

CVE-2026-2500 Moyenne · 4,4
Quick Playground

Quick Playground <= 1.3.4 – Authenticated (Administrator+) Arbitrary File Read via 'filename' Parameter

The Quick Playground plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.4. This is due to the `qckply_data()` function passing the user-supplied `filename` POST parameter directly to `file_get_contents()` without any validation,…

Versions affectées

*-1.3.4

Correctif

1.3.5

Publication

05/06/2026

CVE-2026-6403 Élevée · 7,5
Quick Playground

Quick Playground <= 1.3.3 – Unauthenticated Path Traversal to Arbitrary File Read via 'stylesheet' Parameter

The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is due to insufficient path validation in the qckply_zip_theme() function, which appends a user-controlled 'stylesheet' parameter directly to the…

Versions affectées

*-1.3.3

Correctif

1.3.4

Publication

14/05/2026

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités