Description
The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allowing unauthenticated attackers to overwrite the administrator's stored cloud service connection with an account under their control, disconnecting the legitimate administrator and redirecting the site's cloud template library to attacker-controlled content.
Published: 2026-08-07
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the Templately WordPress plugin before version 3.7.1. A request handler does not perform an authorization check, enabling an unauthenticated attacker to overwrite the administrator’s stored cloud service connection with an account controlled by the attacker. This action disconnects the legitimate administrator and redirects the site’s cloud template library to attacker‑controlled content, effectively allowing arbitrary template inclusion at the site’s discretion.

Affected Systems

WordPress sites that have the Templately plugin installed with a version earlier than 3.7.1. The plugin’s author is listed simply as Unknown:Templately, and no specific operating systems or additional products are mentioned in the data.

Risk and Exploitability

The exploit does not require any privileged credentials and can be performed remotely over the web. Attackers can target the exposed request handler to overwrite the administrator connection. The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 6.5 indicates medium severity, and the fact that no authentication is required and the impact includes disconnection of the administrator and substitution of trusted templates indicates a high risk of abuse. The lack of an authorization check directly aligns with CWE‑862, which is known to facilitate unauthorized privilege escalation and data manipulation.

Generated by OpenCVE AI on August 7, 2026 at 21:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Templately plugin update (v3.7.1 or later) to restore the missing authorization checks
  • If an immediate update is not feasible, deactivate or remove the Templately plugin until the patch is applied
  • After remediation, revoke and reset any shared cloud service credentials and audit the template library for unauthorized changes

Generated by OpenCVE AI on August 7, 2026 at 21:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 07 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Templately
Templately templately
Wordpress
Wordpress wordpress
Vendors & Products Templately
Templately templately
Wordpress
Wordpress wordpress

Fri, 07 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 07 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allowing unauthenticated attackers to overwrite the administrator's stored cloud service connection with an account under their control, disconnecting the legitimate administrator and redirecting the site's cloud template library to attacker-controlled content.
Title Templately < 3.7.1 - Unauthenticated Administrator Templately Cloud Connection Overwrite
References

Subscriptions

Templately Templately
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-07T17:38:44.503Z

Reserved: 2026-07-10T07:08:11.518Z

Link: CVE-2026-15359

cve-icon Vulnrichment

Updated: 2026-08-07T17:38:04.037Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T06:16:55.460

Modified: 2026-08-26T16:31:16.753

Link: CVE-2026-15359

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T21:30:18Z

Weaknesses