Impact
The vulnerability exists in the Templately WordPress plugin before version 3.7.1. A request handler does not perform an authorization check, enabling an unauthenticated attacker to overwrite the administrator’s stored cloud service connection with an account controlled by the attacker. This action disconnects the legitimate administrator and redirects the site’s cloud template library to attacker‑controlled content, effectively allowing arbitrary template inclusion at the site’s discretion.
Affected Systems
WordPress sites that have the Templately plugin installed with a version earlier than 3.7.1. The plugin’s author is listed simply as Unknown:Templately, and no specific operating systems or additional products are mentioned in the data.
Risk and Exploitability
The exploit does not require any privileged credentials and can be performed remotely over the web. Attackers can target the exposed request handler to overwrite the administrator connection. Although an EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the fact that no authentication is required and the impact includes disconnection of the administrator and substitution of trusted templates indicates a high risk of abuse. The lack of an authorization check directly aligns with CWE‑284, which is known to facilitate unauthorized privilege escalation and data manipulation.
OpenCVE Enrichment