Arbitrary File Upload Vulnerability in TemplateSpare by WordPress
CVE-2026-57658

9.1CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
26 June 2026

What is CVE-2026-57658?

The TemplateSpare plugin for WordPress, versions up to 4.2.0, contains a vulnerability that allows authenticated administrators to upload arbitrary files. This issue could potentially lead to remote code execution, putting the integrity and confidentiality of the site's data at risk. It is crucial for users of affected versions to promptly update their plugins to mitigate this security risk.

Affected Version(s)

TemplateSpare <= 4.2.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program
.