Vulnerabilities / AM LottiePlayer / WPSEC-2026-0754

AM LottiePlayer <= 4.2.4 - Authenticated (Author+) Denial of Service via .lottie Archive Decompression Bomb

Medium 6.5 CWE-409Fixed in 4.2.5
ID
WPSEC-2026-0754
Plugin
AM LottiePlayer (am-lottieplayer)
Affected
from 3.5.0 before 4.2.5
Remediation
Update to 4.2.5 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness
CWE-409
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
Attack surface
AM LottiePlayer on WPSec AttackSurface
Fix released
Published

Description

The AM LottiePlayer plugin for WordPress is vulnerable to Uncontrolled Resource Consumption via the .lottie/dotLottie upload validation in all versions up to, and including, 4.2.4. This is due to uploaded archives being fully extracted into the server's temporary directory with no limit on entry count, file size, total uncompressed size or compression ratio, and the extracted files are never removed. This makes it possible for authenticated attackers, with Author-level access and above, to upload a decompression bomb that fills the server's disk and uses up CPU, causing a denial of service.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0