OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-75799

CRITICAL · CVSS 9 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The YAHMAN Add-ons plugin for WordPress prior to version 0.9.31 is vulnerable due to inadequate validation of remote file types, enabling unauthenticated attackers to upload arbitrary PHP files to a publicly accessible directory. This flaw can lead to remote code execution if the feature allowing file caching is enabled. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-75799
Severity
CRITICAL
CVSS
9
EPSS
0.26%
WordPress

Original NVD Description

The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled.