Ad

CVE-2026-18438

HIGH CVSS 3.1: 8,8
Обновлено 15 августа 2026
WordPress
Параметр Значение
CVSS 8,8 (HIGH)
Тип уязвимости CWE-434 (Неограниченная загрузка файлов)
Поставщик WordPress
Публичный эксплойт Нет

The Templately — Библиотека шаблонов Elementor и Gutenberg: более 6500 бесплатных и готовых шаблонов и облако! Плагин для WordPress уязвим к удаленному выполнению кода во всех версиях до 3.7.1 включительно через функцию fetch_remote_file. Это связано с несоответствием имени файла и места назначения в fetch_remote_file, где проверка типа файла выполняется по имени файла Content-Disposition, контролируемому злоумышленником, а не по имени файла назначения, полученному из URL-пути. Это позволяет аутентифицированным злоумышленникам с доступом на уровне участника и выше выполнять код на сервере.

Полиглотный файл GIF+PHP проходит проверку wp_check_filetype_and_ext как image/gif через имя файла Content-Disposition, в то время как фактический путь назначения записывается с расширением .php, полученным из пути URL-адреса, полностью минуя шлюз возможности unfiltered_upload. Затронутые конечные точки доступны на этом уровне привилегий, поскольку весь REST API Templately, включая конечные точки облачного импорта, использованные в этой атаке (/templately/v1/clouds/upload и /templately/v1/insert), авторизован только с помощью проверки current_user_can('delete_posts') без каких-либо требований к возможностям администратора или Manage_options. Тот же шлюз разрешений также позволяет участнику перезаписать глобальное облачное соединение Templately сайта через конечную точку /templately/v1/login с параметром global_signin, установленным в true.

Полное исправление должно как исправить fetch_remote_file для проверки типа файла на соответствие фактическому имени файла назначения, а не заголовку Content-Disposition (и избежать получения пути записи из URL-адреса запроса), так и ограничить изменение состояния шаблонных REST-маршрутов соответствующими возможностями уровня администратора.

Показать оригинальное описание (EN)

The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.7.1 via the fetch_remote_file function. This is due to a filename validation/destination mismatch in fetch_remote_file, where file type validation is performed against the attacker-controlled Content-Disposition filename rather than the URL-path-derived destination filename. This makes it possible for authenticated attackers, with contributor-level access and above, to execute code on the server. A GIF+PHP polyglot file passes wp_check_filetype_and_ext validation as image/gif via the Content-Disposition filename, while the actual destination path is written with a .php extension derived from the URL path, bypassing the unfiltered_upload capability gate entirely. The affected endpoints are reachable at this privilege level because Templately's entire REST API — including the cloud import endpoints used in this attack (/templately/v1/clouds/upload and /templately/v1/insert) — is authorized only by a current_user_can('delete_posts') check, with no administrator or manage_options capability requirement. The same permission gate also allows a contributor to overwrite the site's global Templately cloud connection via the /templately/v1/login endpoint with global_signin set to true. A complete remediation should both correct fetch_remote_file to validate the file type against the actual destination filename rather than the Content-Disposition header (and avoid deriving the write path from the request URL), and restrict state-changing Templately REST routes to an appropriate administrator-level capability.

Характеристики атаки

Способ атаки
По сети
Атака возможна удалённо
Сложность
Низкая
Легко эксплуатировать
Нужны права
Низкие
Нужны базовые права
Участие пользователя
Не требуется
Не нужно действие пользователя

Последствия

Конфиденциальность
Высокое
Полная утечка данных
Целостность
Высокое
Полная модификация данных
Доступность
Высокое
Полный отказ в обслуживании

Строка CVSS v3.1

Уязвимые продукты

wpdevteam:templately – elementor & gutenberg template library: 6500+ free & pro ready templates and cloud!

Ссылки 18

https://plugins.trac.wordpress.org/browser/templately/tags/3.6.5/includes/API/A…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/templately/tags/3.6.5/includes/API/I…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/templately/tags/3.6.5/includes/API/M…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/templately/tags/3.6.5/includes/Core/…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/templately/tags/3.6.5/includes/Core/…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/templately/tags/3.6.5/includes/Core/…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/templately/tags/3.6.5/includes/Core/…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/templately/tags/3.7.1/includes/API/A…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/templately/tags/3.7.1/includes/API/I…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/templately/tags/3.7.1/includes/API/M…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/templately/tags/3.7.1/includes/Core/…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/templately/tags/3.7.1/includes/Core/…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/templately/tags/3.7.1/includes/Core/…
security@wordfence.com
https://plugins.trac.wordpress.org/browser/templately/tags/3.7.1/includes/Core/…
security@wordfence.com
https://plugins.trac.wordpress.org/changeset/3636643/templately/trunk/includes/…
security@wordfence.com
https://plugins.trac.wordpress.org/changeset?old_path=%2Ftemplately/tags/3.7.1&…
security@wordfence.com
https://plugins.trac.wordpress.org/changeset?reponame=&new=3636643%40templately…
security@wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/4e68b2f2-12e4-4ff2-91…
security@wordfence.com