CVE-2026-75799

LOWCVSS 9.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-24: 109-24
Referenced assets1 URL
By indicator
Full discourse1 post
  • Rıdvan Yağlı@ridvanyagli

    🔴 WordPress YAHMAN Add-ons'ta kritik RCE açığı CVE-2026-75799, 0.9.31 öncesi YAHMAN Add-ons sürümlerinde, kimlik doğrulaması gerektirmeden keyfi PHP dosyası yüklenmesine ve RCE'ye yol açıyor. Açık, Blog Card Cache özelliği üzerinden istismar edilebiliyor. CVSS 3.1: 9.0 (Critical) Çözüm: 0.9.31 ve üzeri sürüme güncellemek. https://wpscan.com/vulnerability/b12397e7-5d9b-42bf-bd31-5d3401bc4600/

    00030542
    2.4K followersView on X

Explore more