CVE-2026-75799
YAHMAN Add-ons < 0.9.31 - Unauthenticated Arbitrary File Upload via Blog Card Cache
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled.
| Vendor | unknown |
| Product | yahman add-ons |
| Published | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown yahman add-ons
Be the first to know when new unknown vulnerabilities affecting unknown yahman add-ons are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / YAHMAN Add-ons
0 < 0.9.31
References
Credits
Artus KG WPScan