CVE-2026-18438
8.8WPDevTeam · Templately – Elementor & Gutenberg Template Library
The Templately plugin for WordPress is vulnerable to Remote Code Execution due to unrestricted file uploads, allowing authenticated attackers to execute arbitrary code.
Executive summary
The Templately plugin for WordPress contains a critical Remote Code Execution vulnerability that could allow an authenticated attacker to compromise the host server.
Vulnerability
The plugin suffers from an unrestricted file upload vulnerability (CWE-434), which enables an authenticated user with low privileges to upload and execute malicious files on the server.
Business impact
Successful exploitation allows an attacker to gain full control over the WordPress installation, potentially leading to unauthorized data access, site defacement, or lateral movement within the network. With a CVSS score of 8.8, this vulnerability poses a high risk to organizational security and business continuity.
Remediation
Immediate Action: Update the Templately plugin to version 3.7.2 or later immediately.
Proactive Monitoring: Monitor server logs for unusual file uploads or execution patterns originating from plugin directories.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized file uploads and suspicious script execution.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the severity of Remote Code Execution vulnerabilities, it is imperative to apply the provided patch without delay. Organizations should prioritize updating all instances of the Templately plugin to version 3.7.2 to mitigate the risk of unauthorized code execution.