# AM LottiePlayer <= 4.2.4 - Authenticated (Author+) Denial of Service via .lottie Archive Decompression Bomb

- **ID:** WPSEC-2026-0754
- **Plugin:** AM LottiePlayer (`am-lottieplayer`), https://wordpress.org/plugins/am-lottieplayer/
- **Affected versions:** from 3.5.0 before 4.2.5
- **Fixed in:** 4.2.5 (Update to 4.2.5 or later.)
- **Severity:** Medium 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
- **Weakness:** CWE-409
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/am-lottieplayer
- **Fix released:** 2026-10-08
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0754/

## Description

The AM LottiePlayer plugin for WordPress is vulnerable to Uncontrolled Resource Consumption via the .lottie/dotLottie upload validation in all versions up to, and including, 4.2.4. This is due to uploaded archives being fully extracted into the server's temporary directory with no limit on entry count, file size, total uncompressed size or compression ratio, and the extracted files are never removed. This makes it possible for authenticated attackers, with Author-level access and above, to upload a decompression bomb that fills the server's disk and uses up CPU, causing a denial of service.

## References

- https://wpsec.com/vuln/WPSEC-2026-0754/
- https://plugins.svn.wordpress.org/am-lottieplayer/tags/4.2.5/
- https://wordpress.org/plugins/am-lottieplayer/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0754/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
