{"id":"CVE-2026-75799","published":"2026-09-23T06:17:01.710","lastModified":"2026-09-23T18:13:31.210","description":"The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled.","cvssScore":9,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-94"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/b12397e7-5d9b-42bf-bd31-5d3401bc4600/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated attackers to write arbitrary PHP files on the server, leading to Remote Code Execution (RCE) when the caching feature is enabled.","exploitability":"Exploitation is relatively straightforward as it requires only enabling the caching feature and uploading a malicious PHP file.","blast_radius":"If exploited, the impact is critical as it can lead to full server compromise and unauthorized execution of arbitrary code.","remediation":"Upgrade to version 0.9.31 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","web","php","cve","wordpress"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T08:53:48.796Z"}}