Executive brief
Templatiq is a WordPress plugin that allows website building and content management. A contributor-level user (a person with mid-level permissions on a WordPress site) can upload arbitrary files to the server, potentially allowing complete site takeover and malware installation. This vulnerability affects all versions up to and including 0.2.5, with no official patch currently available.
Technical details
The vulnerability is an arbitrary file upload flaw in the Templatiq WordPress plugin affecting versions 0.2.5 and earlier. The vulnerability allows users with contributor privileges (a standard WordPress user role) to upload malicious files without proper validation or restrictions. An attacker with contributor access can upload executable files or malicious scripts to the server, leading to remote code execution and complete server compromise. No official patch has been released; users should update or disable the plugin and apply temporary mitigations via security plugins.
Affected products
- Templatiq Templatiq <=0.2.5
Timeline
- 2026-08-18: disclosed
- 2026-01-23: other: Reported by daroo on 2026-01-23