Medium severity5.3NVD Advisory· Published Jan 10, 2026· Updated Apr 15, 2026
CVE-2026-0831
CVE-2026-0831
Description
The Templately plugin for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 3.4.8. This is due to inadequate input validation in the save_template_to_file() function where user-controlled parameters like session_id, content_id, and ai_page_ids are used to construct file paths without proper sanitization. This makes it possible for unauthenticated attackers to write arbitrary .ai.json files to locations within the uploads directory.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- plugins.trac.wordpress.org/browser/templately/tags/3.4.5/includes/API/AIContent.phpnvd
- plugins.trac.wordpress.org/browser/templately/tags/3.4.5/includes/Core/Importer/Utils/AIUtils.phpnvd
- plugins.trac.wordpress.org/changeset/3426051/nvd
- www.wordfence.com/threat-intel/vulnerabilities/id/778242f4-5dfa-4d72-a032-8b5521c5b8cenvd
News mentions
0No linked articles in our index yet.