Authorization Bypass in Templately WordPress Plugin Affects User Security
CVE-2026-15359
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 7 August 2026
Badges
What is CVE-2026-15359?
The Templately WordPress plugin prior to version 3.7.1 is susceptible to an authorization bypass. This vulnerability allows unauthorized attackers to exploit a lack of proper checks on certain request handlers. By leveraging this flaw, an attacker can replace the legitimate administrator's stored cloud service connection with an account they control. This not only disconnects the legitimate administrator but also hijacks the cloud template library, redirecting it to content managed by the attacker. This poses a significant risk to the security and integrity of websites utilizing this plugin.
Affected Version(s)
Templately 0 < 3.7.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.