Impact
The YAHMAN Add-ons WordPress plugin before version 0.9.31 fails to validate the type of remote files cached in a publicly accessible directory. This flaw allows attackers who need not authenticate to upload arbitrary PHP files, which can then be executed with the web server’s privileges, resulting in full remote code execution. The weakness is a code injection flaw identified as CWE-94.
Affected Systems
WordPress sites that have the YAHMAN Add-ons plugin installed with a version older than 0.9.31 and that use the blog card cache feature. The vulnerability applies to any deployment where the plugin is active and the cache directory is writable by the web server.
Risk and Exploitability
The CVSS score of 9 indicates a high‑severity vulnerability combined with the ability to write files without authentication. Although the EPSS score is unavailable, the lack of authentication and public access to the cache directory suggest a reasonable likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. An attacker likely gains remote access through the vulnerable blog card cache feature, which writes downloaded content directly to the web root. Successful exploitation results in full control of the affected server.
OpenCVE Enrichment