{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/templately--elementor--gutenberg-template-library/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-18438"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Templately – Elementor \u0026 Gutenberg Template Library"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Templately"],"content_html":"\u003cp\u003eThe Templately - Elementor \u0026amp; Gutenberg Template Library plugin for WordPress (versions 3.7.1 and below) is susceptible to remote code execution (RCE) due to a flaw in the \u003ccode\u003efetch_remote_file\u003c/code\u003e function. The plugin fails to validate file types against the actual destination path, instead relying on the attacker-controlled Content-Disposition header. An attacker with contributor-level permissions can craft a malicious GIF+PHP polyglot file that bypasses server-side checks. Because the plugin derives the final write path from the request URL, the file is saved with a .php extension rather than the expected image type. Furthermore, Templately's REST API endpoints (including those used for cloud imports) are improperly gated by the \u003ccode\u003edelete_posts\u003c/code\u003e capability, allowing users with low-level privileges to perform sensitive operations. This vulnerability significantly impacts WordPress sites using the plugin by providing a clear path to full system compromise for authenticated users.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the WordPress site with Contributor-level access or higher.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a GIF/PHP polyglot file designed to bypass \u003ccode\u003ewp_check_filetype_and_ext\u003c/code\u003e validation.\u003c/li\u003e\n\u003cli\u003eAttacker sends a POST request to the vulnerable Templately REST API endpoint, specifically \u003ccode\u003e/templately/v1/clouds/upload\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe request includes a manipulated Content-Disposition header identifying the file as an image/gif to satisfy validation logic.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003efetch_remote_file\u003c/code\u003e function processes the request and writes the payload to the server.\u003c/li\u003e\n\u003cli\u003eDue to the destination path derivation flaw, the file is saved with a .php extension instead of an image extension.\u003c/li\u003e\n\u003cli\u003eAttacker triggers the uploaded PHP file via a direct HTTP request to the web server to achieve remote code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in unauthorized remote code execution on the underlying web server. This allows an attacker to execute system commands, access the WordPress database, steal sensitive information, or further compromise the hosting environment. Organizations using Templately versions 3.7.1 or older are at risk of complete site takeover by any authenticated user with contributor-level access.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Templately plugin to the latest available version to patch the \u003ccode\u003efetch_remote_file\u003c/code\u003e validation logic.\u003c/li\u003e\n\u003cli\u003eAudit WordPress user permissions to identify and restrict excessive contributor-level accounts.\u003c/li\u003e\n\u003cli\u003eDeploy the provided web server detection rules to identify malicious requests targeting Templately REST API endpoints.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests to \u003ccode\u003e/templately/v1/clouds/upload\u003c/code\u003e that result in unusual file extensions or requests from authenticated accounts with limited roles.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-15T10:18:16Z","date_published":"2026-08-15T10:18:16Z","id":"https://feed.craftedsignal.io/briefs/2026-08-templately-rce/","summary":"Authenticated contributors can execute arbitrary code via the Templately plugin by bypassing file type validation through a GIF/PHP polyglot file.","title":"Remote Code Execution in Templately WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-templately-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Templately – Elementor \u0026 Gutenberg Template Library","version":"https://jsonfeed.org/version/1.1"}