Unrated severityNVD Advisory· Published Sep 23, 2026
CVE-2026-75799
CVE-2026-75799
Description
The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled.
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.