Remote Code Execution Vulnerability in Templately Plugin for WordPress
CVE-2026-18438

8.8HIGH

What is CVE-2026-18438?

The Templately plugin for WordPress has a vulnerability that allows authenticated users with contributor-level access and above to execute arbitrary code on the server. This arises from a validation flaw in the fetch_remote_file function, where the script fails to correctly validate the file type against the actual destination filename. Consequently, attackers can exploit the filename validation using specially crafted Content-Disposition headers. This flaw allows the execution of malicious files, posing a significant threat to the security of WordPress sites running compromised versions of the plugin. Proper remediation requires both a code correction to enhance filename validation and a restriction on access to sensitive REST API endpoints.

Affected Version(s)

Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! 0 <= 3.7.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dmitrii Ignatyev
.