← Back to search

CVE-2026-75799

9 CRITICAL

Published 2026-09-23 · Updated 2026-09-23

AI risk analysis

Summary
The flaw allows unauthenticated attackers to write arbitrary PHP files on the server, leading to Remote Code Execution (RCE) when the caching feature is enabled.
Exploitability
Exploitation is relatively straightforward as it requires only enabling the caching feature and uploading a malicious PHP file.
Blast radius
If exploited, the impact is critical as it can lead to full server compromise and unauthorized execution of arbitrary code.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to version 0.9.31 or later.
rcewebphpcvewordpress

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-94

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.