EUVD Vulnerability Catalog

EUVD-2026-85024

Severity: CRITICAL Base Score: 9 CVSS Version: 3.1

Vulnerability Description

The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled.

CVSS Vector Analysis

Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

▪ Attack Vector (AV): Network
▪ Attack Complexity (AC): High
▪ Privileges Required (PR): None
▪ User Interaction (UI): None
▪ Scope (S): Changed
▪ Confidentiality Impact (C): High
▪ Integrity Impact (I): High
▪ Availability Impact (A): High

Affected Vendors & Systems

Vendor Unknown

References & Advisory Links

Metadata Profile

Database Authority

European Union Agency for Cybersecurity (ENISA) EUVD

Assigner

WPScan

EPSS Probability

0

Known Aliases
GHSA-ppcx-fj6x-46xf CVE-2026-75799
Published On

2026-09-23

Last Updated

2026-09-23