BUGFLARE
Threat intelligence and bug bounty research platform. Live vulnerability data, in-app writeup reading, and program tracking — aggregated from trusted public sources.
© 2026 Bugflare. Publishers retain authorship; always verify on the source.
bugflare.site
CVE-2026-18438 · HIGH · Bugflare
CVE-2026-18438 HIGH CVE: CVE-2026-18438 - The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud Sign in to save EPSS
N/A
Exploit Prediction Score
Exploitability
No EPSS data available
Description The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.7.1 via the fetch_remote_file function. This is due to a filename validation/destination mismatch in fetch_remote_file, where file type validation is performed against the attacker-controlled Content-Disposition filename rather than the URL-path-derived destination filename. This makes it possible for authenticated attackers, with contributor-level access and above, to execute code on the server. A GIF+PHP polyglot file passes wp_check_filetype_and_ext validation as image/gif via the Content-Disposition filename, while the actual destination path is written with a .php extension derived from the URL path, bypassing the unfiltered_upload capability gate entirely. The affected endpoints ar...
Affected Packages No package data available.
Related references Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).
https://plugins.trac.wordpress.org/browser/templately/tags/3.6.5/includes/API/API.php#L128 https://plugins.trac.wordpress.org/browser/templately/tags/3.6.5/includes/API/Import.php#L78 https://plugins.trac.wordpress.org/browser/templately/tags/3.6.5/includes/API/MyClouds.php#L103 https://plugins.trac.wordpress.org/browser/templately/tags/3.6.5/includes/Core/Importer/WPImport.php#L1200 https://plugins.trac.wordpress.org/browser/templately/tags/3.6.5/includes/Core/Importer/WPImport.php#L1391 https://plugins.trac.wordpress.org/browser/templately/tags/3.6.5/includes/Core/Importer/WPImport.php#L1423 https://plugins.trac.wordpress.org/browser/templately/tags/3.6.5/includes/Core/Platform/Gutenberg.php#L177 https://plugins.trac.wordpress.org/browser/templately/tags/3.7.1/includes/API/API.php#L128 https://plugins.trac.wordpress.org/browser/templately/tags/3.7.1/includes/API/Import.php#L78 https://plugins.trac.wordpress.org/browser/templately/tags/3.7.1/includes/API/MyClouds.php#L103 https://plugins.trac.wordpress.org/browser/templately/tags/3.7.1/includes/Core/Importer/WPImport.php#L1200 Source
Originally published by NVD (nvd.nist.gov) .
CVE metadata is aggregated from public vulnerability databases. Scores and descriptions remain attributed to their origin feeds.
https://plugins.trac.wordpress.org/browser/templately/tags/3.7.1/includes/Core/Importer/WPImport.php#L1391
https://plugins.trac.wordpress.org/browser/templately/tags/3.7.1/includes/Core/Importer/WPImport.php#L1423
https://plugins.trac.wordpress.org/browser/templately/tags/3.7.1/includes/Core/Platform/Gutenberg.php#L177
https://plugins.trac.wordpress.org/changeset/3636643/templately/trunk/includes/Core/Importer/WPImport.php
https://plugins.trac.wordpress.org/changeset?old_path=%2Ftemplately/tags/3.7.1&new_path=%2Ftemplately/tags/3.7.2
https://plugins.trac.wordpress.org/changeset?reponame=&new=3636643%40templately%2Ftags%2F3.7.2&old=3624408%40templately%…
https://www.wordfence.com/threat-intel/vulnerabilities/id/4e68b2f2-12e4-4ff2-919d-26d6b21acd03?source=cve