What is CVE-2026-16060?
The CVE-2026-16060 vulnerability in the 'Insert or Embed Articulate Content' WordPress plugin allows an Editor-level user to upload a server-executable file to a public directory due to insufficient validation of uploaded archives. This can lead to remote code execution.
Azərbaycanca: WordPress üçün 'Insert or Embed Articulate Content' plaginində aşkarlanan CVE-2026-16060 zəifliyi yüklənən arxiv faylının düzgün yoxlanılmaması səbəbindən Editor səviyyəli istifadəçiyə ictimai qovluğa serverdə icra oluna bilən fayl yükləməyə imkan verir. Bu, uzaqdan kod icrasına (remote code execution) yol aça bilər.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
What causes the CVE-2026-16060 vulnerability in the 'Insert or Embed Articulate Content' plugin for WordPress?
The vulnerability is caused by insufficient validation of uploaded archives.
What privilege level of user can exploit the CVE-2026-16060 vulnerability?
An Editor-level user can exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.