CRITICAL 9.0 CVE-2026-75799 Published 23 Sept 2026

YAHMAN Add-ons WordPress Plugin Arbitrary PHP File Upload RCE

Worried this affects your website?

The YAHMAN Add-ons WordPress plugin before 0.9.31 has a remote file upload vulnerability.

The plugin does not validate the type of remote files it caches in a publicly accessible directory. This allows unauthenticated attackers to write arbitrary PHP files on the server.

Successful exploitation can achieve remote code execution when the relevant feature is enabled.

  • Affects versions before 0.9.31.
  • Requires the relevant feature to be enabled.
  • Impact: arbitrary PHP file write and remote code execution.

Reference: CVE-2026-75799 on NVD

← Back to Security News