CVE-2026-75799
Gravedad CVSS v3.1:
CRÍTICA
Tipo:
CWE-94
Control incorrecto de generación de código (Inyección de código)
Fecha de publicación:
23/09/2026
Última modificación:
23/09/2026
Descripción
*** Pendiente de traducción *** The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled.
Impacto
Puntuación base 3.x
9.00
Gravedad 3.x
CRÍTICA


