cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches foryahman-add-ons yahman-add-ons

Direction: descending
Sep 25, 2026

YAHMAN Add-ons # CVE-2026-75799

CVE, Research URL

CVE-2026-75799

Application

YAHMAN Add-ons

Date
Sep 23, 2026
Research Description
The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled.
Affected versions
max 0.9.31.
Status
vulnerable
Jul 05, 2024

YAHMAN Add-ons # 04932eef8b83d4768060ec8134143e75df87ccfc

Application

YAHMAN Add-ons

Date
Jul 03, 2024
Research Description
YAHMAN Add-ons [yahman-add-ons] < 0.9.29 WordPress YAHMAN Add-ons Plugin <= 0.9.28 is vulnerable to Backdoor <p>WordPress YAHMAN Add-ons Plugin <= 0.9.28 is vulnerable to Backdoor</p><p>Software: YAHMAN Add-ons</p><p>Link: https://wordpress.org/plugins/yahman-add-ons/#developers</p><p>Affected Version <= 0.9.28</p><p>Fixed in version 0.9.29 </p>
Affected versions
max 0.9.29.
Status
vulnerable