Remote Code Execution Vulnerability in Templately Plugin for WordPress
CVE-2026-18438
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 15 August 2026
What is CVE-2026-18438?
The Templately plugin for WordPress has a vulnerability that allows authenticated users with contributor-level access and above to execute arbitrary code on the server. This arises from a validation flaw in the fetch_remote_file function, where the script fails to correctly validate the file type against the actual destination filename. Consequently, attackers can exploit the filename validation using specially crafted Content-Disposition headers. This flaw allows the execution of malicious files, posing a significant threat to the security of WordPress sites running compromised versions of the plugin. Proper remediation requires both a code correction to enhance filename validation and a restriction on access to sensitive REST API endpoints.
Affected Version(s)
Templately β Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! 0 <= 3.7.1