YAHMAN Add-ons, CVE-2026-75799
- CVE, Research URL
- Home page URL
- Application
- Published on
- Sep 23, 2026
- Research Description
- The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled.
- Affected versions
-
max 0.9.31.
- Status
-
vulnerable
| Previous vulnerability researches |
|---|
| YAHMAN Add-ons (04932eef8b83d4768060ec8134143e75df87ccfc) , Jul 05, 2024 |
| YAHMAN Add-ons (CVE-2026-75799) , Sep 25, 2026 |