What is CVE-2026-15359?
The CVE-2026-15359 vulnerability involves a missing authorisation check on a request handler in the Templately WordPress plugin versions prior to 3.7.1. This flaw allows unauthenticated attackers to overwrite the administrator's stored cloud service connection with an account under their control, disconnecting the legitimate admin. Users should immediately update the Templately plugin to version 3.7.1 or later.
Azərbaycanca: CVE-2026-15359, Templately WordPress plaginin 3.7.1 versiyasından əvvəlki versiyalarda avtorizasiya yoxlanışı olmayan bir sorğu idarəedicisini əhatə edir. Bu, autentifikasiya olunmamış hücumçulara administratorun bulud xidməti əlaqəsini öz nəzarətlərindəki hesabla əvəz etməyə imkan verir. İstifadəçilər dərhal Templately plaginini 3.7.1 və ya daha yuxarı versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Templately plugin are affected by CVE-2026-15359?
The vulnerability affects all versions of the Templately WordPress plugin prior to version 3.7.1.
What can an unauthenticated attacker achieve by exploiting CVE-2026-15359?
An unauthenticated attacker can overwrite the administrator's stored cloud service connection with an account under their control, disconnecting the legitimate admin.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.