The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled. | |
| Title | YAHMAN Add-ons < 0.9.31 - Unauthenticated Arbitrary File Upload via Blog Card Cache | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-23T11:00:20.091Z
Reserved: 2026-08-18T09:17:31.640Z
Link: CVE-2026-75799
Updated: 2026-09-23T10:38:58.070Z
Status : Received
Published: 2026-09-23T06:17:01.710
Modified: 2026-09-23T11:17:11.110
Link: CVE-2026-75799
No data.
OpenCVE Enrichment
No data.
Weaknesses