CyberRota Analysis
AI-GeneratedThe YAHMAN Add-ons plugin for WordPress prior to version 0.9.31 is vulnerable due to inadequate validation of remote file types, enabling unauthenticated attackers to upload arbitrary PHP files to a publicly accessible directory. This flaw can lead to remote code execution if the feature allowing file caching is enabled. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of exploitation.
Original NVD Description
The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled.