PT-2026-2031 · WordPress · Templately

Wpdevteam

·

Publicado

2026-01-10

·

Atualizado

2026-01-10

·

CVE-2026-0831

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Templately versions prior to 3.4.9
Description The Templately plugin for WordPress is susceptible to an arbitrary file write issue. This is a result of insufficient input validation within the save template to file() function. User-controlled parameters, including session id, content id, and ai page ids, are utilized to create file paths without appropriate sanitization. This allows unauthenticated attackers to write arbitrary .ai.json files to locations within the uploads directory.
Recommendations Update to Templately version 3.4.9 or later.

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-0831

Produtos afetados

Templately