rootpwn

critical · CVSS v3 9 · EPSS 0.00235

CVE-2026-75799

The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly…

Description

The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled.

Scores

Severity
critical
CVSS v2
7.6
CVSS v3
9
CVSS v4
EPSS
0.00235

← All CVEs