Vulnerabilities and security researches foryahman-add-ons yahman-add-ons
Direction: ascendingJul 05, 2024
YAHMAN Add-ons # 04932eef8b83d4768060ec8134143e75df87ccfc
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 03, 2024
- Research Description
- YAHMAN Add-ons [yahman-add-ons] < 0.9.29 WordPress YAHMAN Add-ons Plugin <= 0.9.28 is vulnerable to Backdoor <p>WordPress YAHMAN Add-ons Plugin <= 0.9.28 is vulnerable to Backdoor</p><p>Software: YAHMAN Add-ons</p><p>Link: https://wordpress.org/plugins/yahman-add-ons/#developers</p><p>Affected Version <= 0.9.28</p><p>Fixed in version 0.9.29 </p>
- Affected versions
-
max 0.9.29.
- Status
-
vulnerable
Sep 25, 2026
YAHMAN Add-ons # CVE-2026-75799
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 23, 2026
- Research Description
- The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled.
- Affected versions
-
max 0.9.31.
- Status
-
vulnerable