AM LottiePlayer <= 4.2.4 - Authenticated (Author+) Denial of Service via .lottie Archive Decompression Bomb
- ID
- WPSEC-2026-0754
- Plugin
- AM LottiePlayer (am-lottieplayer)
- Affected
- from 3.5.0 before 4.2.5
- Remediation
- Update to 4.2.5 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Weakness
- CWE-409
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
- Attack surface
- AM LottiePlayer on WPSec AttackSurface
- Fix released
- Published
Description
The AM LottiePlayer plugin for WordPress is vulnerable to Uncontrolled Resource Consumption via the .lottie/dotLottie upload validation in all versions up to, and including, 4.2.4. This is due to uploaded archives being fully extracted into the server's temporary directory with no limit on entry count, file size, total uncompressed size or compression ratio, and the extracted files are never removed. This makes it possible for authenticated attackers, with Author-level access and above, to upload a decompression bomb that fills the server's disk and uses up CPU, causing a denial of service.
References
- https://wpsec.com/vuln/WPSEC-2026-0754/
- https://plugins.svn.wordpress.org/am-lottieplayer/tags/4.2.5/
- https://wordpress.org/plugins/am-lottieplayer/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS