Description
The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allowing unauthenticated attackers to overwrite the administrator's stored cloud service connection with an account under their control, disconnecting the legitimate administrator and redirecting the site's cloud template library to attacker-controlled content.
Published: 2026-08-07
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the Templately WordPress plugin before version 3.7.1. A request handler does not perform an authorization check, enabling an unauthenticated attacker to overwrite the administrator’s stored cloud service connection with an account controlled by the attacker. This action disconnects the legitimate administrator and redirects the site’s cloud template library to attacker‑controlled content, effectively allowing arbitrary template inclusion at the site’s discretion.

Affected Systems

WordPress sites that have the Templately plugin installed with a version earlier than 3.7.1. The plugin’s author is listed simply as Unknown:Templately, and no specific operating systems or additional products are mentioned in the data.

Risk and Exploitability

The exploit does not require any privileged credentials and can be performed remotely over the web. Attackers can target the exposed request handler to overwrite the administrator connection. Although an EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the fact that no authentication is required and the impact includes disconnection of the administrator and substitution of trusted templates indicates a high risk of abuse. The lack of an authorization check directly aligns with CWE‑284, which is known to facilitate unauthorized privilege escalation and data manipulation.

Generated by OpenCVE AI on August 7, 2026 at 07:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Templately plugin update (v3.7.1 or later) to restore the missing authorization checks
  • If an immediate update is not feasible, deactivate or remove the Templately plugin until the patch is applied
  • After remediation, revoke and reset any shared cloud service credentials and audit the template library for unauthorized changes

Generated by OpenCVE AI on August 7, 2026 at 07:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 07 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allowing unauthenticated attackers to overwrite the administrator's stored cloud service connection with an account under their control, disconnecting the legitimate administrator and redirecting the site's cloud template library to attacker-controlled content.
Title Templately < 3.7.1 - Unauthenticated Administrator Templately Cloud Connection Overwrite
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-07T06:00:12.437Z

Reserved: 2026-07-10T07:08:11.518Z

Link: CVE-2026-15359

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T07:30:09Z

Weaknesses