CVE-2026-16060
Received Received - Intake

Remote Code Execution in Insert or Embed Articulate Content WordPress Plugin

Vulnerability report for CVE-2026-16060, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: WPScan

Description

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file into a public directory, resulting in remote code execution on servers configured to execute it.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
articulate insert_or_embed_articulate_content 4.3000000027

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in the Insert or Embed Articulate Content into WordPress plugin up to version 4.3000000027. It fails to properly validate uploaded archive files, allowing an Editor-level user to bypass checks and upload executable files to a public directory. If the server is configured to execute such files, this leads to remote code execution.

Detection Guidance

Check for uploaded files in public directories of WordPress installations using the Insert or Embed Articulate Content plugin. Look for unexpected executable files in directories like /wp-content/uploads/. Review server logs for suspicious file uploads by Editor-level users.

Impact Analysis

If you use this WordPress plugin, an attacker with Editor-level access could upload malicious files to your server. This could allow them to execute arbitrary code, potentially taking control of your website or server. Public-facing servers are at higher risk if configured to run uploaded files.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR (data protection) and HIPAA (health data security) requirements. Compliance may be compromised if sensitive data is exposed or altered due to remote code execution.

Mitigation Strategies

Immediately update the Insert or Embed Articulate Content plugin to the latest version. Remove Editor-level user permissions for untrusted accounts. Scan for and delete any unauthorized executable files in public directories. Monitor server logs for signs of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16060. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart