Executive brief
YAHMAN Add-ons is a WordPress plugin that enables content caching features for websites. The plugin fails to validate file types when caching remote content, allowing attackers to upload arbitrary PHP files to a publicly accessible directory and execute code on the server without authentication.
Technical details
The vulnerability exists in the Blog Card Cache feature, where the plugin does not properly validate the type of remote files before caching them in a public directory. An unauthenticated attacker can exploit this to write a malicious PHP file, achieving remote code execution on the WordPress server. The flaw was patched in version 0.9.31.
Affected products
- YAHMAN Add-ons before 0.9.31
Timeline
- 2026-09-21: disclosed
- 2026-09-21: patched: Fixed in version 0.9.31