cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches foryahman-add-ons yahman-add-ons

Direction: ascending
Jul 05, 2024

YAHMAN Add-ons # 04932eef8b83d4768060ec8134143e75df87ccfc

Application

YAHMAN Add-ons

Date
Jul 03, 2024
Research Description
YAHMAN Add-ons [yahman-add-ons] < 0.9.29 WordPress YAHMAN Add-ons Plugin <= 0.9.28 is vulnerable to Backdoor <p>WordPress YAHMAN Add-ons Plugin <= 0.9.28 is vulnerable to Backdoor</p><p>Software: YAHMAN Add-ons</p><p>Link: https://wordpress.org/plugins/yahman-add-ons/#developers</p><p>Affected Version <= 0.9.28</p><p>Fixed in version 0.9.29 </p>
Affected versions
max 0.9.29.
Status
vulnerable
Sep 25, 2026

YAHMAN Add-ons # CVE-2026-75799

CVE, Research URL

CVE-2026-75799

Application

YAHMAN Add-ons

Date
Sep 23, 2026
Research Description
The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled.
Affected versions
max 0.9.31.
Status
vulnerable