Junglewise Threat Intelligence

CVE-2026-57658: Templatespare TemplateSpare arbitrary file upload

CVE-2026-57658 · Severity: critical · CVSS 9.1 · Published 2026-06-26

Executive brief

TemplateSpare, a WordPress plugin used for site templates, contains a security flaw that allows an administrative user to upload malicious files to the server. If exploited, an attacker with high-level access could upload a 'backdoor' script to take complete control of the website and its underlying data. While the risk is high, it requires the attacker to already have administrator-level privileges on the site.

Technical details

The TemplateSpare plugin for WordPress (versions <= 4.2.0) is vulnerable to an unrestricted arbitrary file upload (CWE-434). This vulnerability allows an authenticated attacker with Administrator-level privileges to upload dangerous file types, such as PHP scripts, to the web server. Because the plugin fails to properly validate file extensions or content, an attacker can achieve remote code execution (RCE) by executing the uploaded files. This issue is addressed in version 4.2.1. The CVSS score of 9.1 reflects the potential for a full site compromise, though the prerequisite of administrative access limits the initial attack surface.

Affected products

  • Templatespare TemplateSpare <= 4.2.0

Timeline

  • 2026-06-10: other: Reported by researcher Ananda Dhakal
  • 2026-06-26: disclosed: Early warning sent to Patchstack customers
  • 2026-06-26: advisory: Public advisory published by Patchstack and NVD
  • 2026-06-26: patched: Patch released in version 4.2.1

References

Related threats