{
 "id": "WPSEC-2026-0754",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0754/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0754/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0754/index.md",
 "title": "AM LottiePlayer <= 4.2.4 - Authenticated (Author+) Denial of Service via .lottie Archive Decompression Bomb",
 "description": "The AM LottiePlayer plugin for WordPress is vulnerable to Uncontrolled Resource Consumption via the .lottie/dotLottie upload validation in all versions up to, and including, 4.2.4. This is due to uploaded archives being fully extracted into the server's temporary directory with no limit on entry count, file size, total uncompressed size or compression ratio, and the extracted files are never removed. This makes it possible for authenticated attackers, with Author-level access and above, to upload a decompression bomb that fills the server's disk and uses up CPU, causing a denial of service.",
 "plugin": {
  "slug": "am-lottieplayer",
  "name": "AM LottiePlayer",
  "full_name": "AM LottiePlayer",
  "wordpress_org": "https://wordpress.org/plugins/am-lottieplayer/",
  "advisories_url": "https://wpsec.com/vuln/plugin/am-lottieplayer/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/am-lottieplayer"
 },
 "type": "DOS",
 "cwe": [
  "CWE-409"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 6.5,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "3.5.0",
    "from_inclusive": true,
    "to": "4.2.5",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 3.5.0 before 4.2.5"
  ]
 },
 "introduced_in": "3.5.0",
 "fixed_in": "4.2.5",
 "remediation": "Update to 4.2.5 or later.",
 "fix_released": "2026-10-08T13:12:21+00:00",
 "published": "2026-10-10T15:41:27+00:00",
 "updated": "2026-10-10T14:54:09.941825+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0754/",
  "https://plugins.svn.wordpress.org/am-lottieplayer/tags/4.2.5/",
  "https://wordpress.org/plugins/am-lottieplayer/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/am-lottieplayer",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-10"
 }
}