CVE-2026-75799 UNKNOWN

CVE-2026-75799

Published: 2026-09-23

Description

The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…