CVE-2026-32474

9.9

wpWax · Templatiq

The Templatiq WordPress plugin is vulnerable to an arbitrary file upload flaw, allowing authenticated contributors to execute malicious code on the server.

Executive summary

The Templatiq plugin for WordPress contains a critical file upload vulnerability that allows authenticated users to achieve remote code execution.

Vulnerability

This vulnerability is an unrestricted file upload flaw (CWE-434) that permits an authenticated user with contributor-level access to upload malicious files, potentially leading to full system compromise.

Business impact

Successful exploitation allows an attacker to bypass security restrictions and execute arbitrary code on the underlying server. Given the CVSS score of 9.9, this vulnerability poses a critical risk to data confidentiality, integrity, and availability, potentially resulting in complete site takeover.

Remediation

Immediate Action: Review the wpWax vendor advisory for the latest security update and apply it immediately to address the file upload restriction.

Proactive Monitoring: Monitor server logs for suspicious file uploads or access to non-standard executable file types within the WordPress uploads directory.

Compensating Controls: Implement a Web Application Firewall (WAF) rule to block unauthorized file uploads and restrict access to the upload functionality based on user roles.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Due to the critical nature of this vulnerability and the potential for remote code execution, organizations must prioritize patching. If an update is not immediately available, restrict plugin access or disable the functionality until a secure version is deployed.

More wpWax CVEs