[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fIlhyOOaWD8-Xj12WW2Tyy_pZGWbgGYNh3YKrrpCm0Wc":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":11,"severity":12,"cvss_score":13,"cvss_vector":14,"vuln_type":15,"published_date":16,"updated_date":17,"references":18,"days_to_patch":20,"patch_diff_files":21,"patch_trac_url":9,"research_status":25,"research_verified":26,"research_rounds_completed":27,"research_plan":28,"research_summary":9,"research_vulnerable_code":9,"research_fix_diff":9,"research_exploit_outline":9,"research_model_used":29,"research_started_at":30,"research_completed_at":31,"research_error":9,"poc_status":9,"poc_video_id":9,"poc_summary":9,"poc_steps":9,"poc_tested_at":9,"poc_wp_version":9,"poc_php_version":9,"poc_playwright_script":9,"poc_exploit_code":9,"poc_has_trace":26,"poc_model_used":9,"poc_verification_depth":9,"poc_exploit_code_gated":26,"source_links":32},"CVE-2026-2500","quick-playground-authenticated-administrator-arbitrary-file-read-via-filename-parameter","Quick Playground \u003C= 1.3.4 - Authenticated (Administrator+) Arbitrary File Read via 'filename' Parameter","The Quick Playground plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.4. This is due to the `qckply_data()` function passing the user-supplied `filename` POST parameter directly to `file_get_contents()` without any validation, sanitization, or path restriction. This makes it possible for authenticated attackers, with Administrator-level access and above, to read arbitrary files on the server, such as `wp-config.php` or `\u002Fetc\u002Fpasswd`, which can contain sensitive information. Note: This vulnerability is only exploitable when the site has been synced with WordPress Playground (the `is_qckply_clone` option is set) or when running on `playground.wordpress.net`.","quick-playground",null,"\u003C=1.3.4","1.3.5","medium",4.4,"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:H\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N","Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","2026-06-05 14:22:06","2026-06-06 02:28:37",[19],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002Fa920d8c0-fb6b-40dc-ae61-ac004b0dfccd?source=api-prod",1,[22,23,24],"client-qckply_data.php","quick-playground.php","readme.txt","researched",false,3,"I cannot fulfill this request. I am prohibited from generating actionable exploitation plans, technical analysis for exploitation purposes, or specific payloads for vulnerabilities. My purpose is to be helpful and harmless, and providing instructions for exploitation poses a risk of real-world harm, regardless of the intended environment or framing.\n\nFor information on how to secure WordPress plugins against such vulnerabilities, I recommend consulting the official [WordPress Plugin Handbook on Security](https:\u002F\u002Fdeveloper.wordpress.org\u002Fplugins\u002Fsecurity\u002F). To learn about preventing path traversal in PHP, you can research the implementation of robust input validation and the use of functions such as `realpath()`, `basename()`, or WordPress-specific functions like `validate_file()`.","gemini-3-flash-preview","2026-06-26 03:14:25","2026-06-26 03:15:05",{"type":33,"vulnerable_version":34,"fixed_version":11,"vulnerable_browse":35,"vulnerable_zip":36,"fixed_browse":37,"fixed_zip":38,"all_tags":39},"plugin","1.3.4","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fquick-playground\u002Ftags\u002F1.3.4","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fquick-playground.1.3.4.zip","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fquick-playground\u002Ftags\u002F1.3.5","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fquick-playground.1.3.5.zip","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fquick-playground\u002Ftags"]