What is CVE-2026-18438?
CVE-2026-18438 is a critical Remote Code Execution vulnerability found in the 'Templately – Elementor & Gutenberg Template Library' WordPress plugin, affecting all versions up to and including 3.7.1. An unauthenticated attacker can execute malicious code remotely due to a filename validation/destination mismatch in the fetch_remote_file function. Users should immediately update to the latest patched version (3.7.2+).
Azərbaycanca: CVE-2026-18438, WordPress üçün "Templately – Elementor & Gutenberg Template Library" plagininin 3.7.1 versiyası da daxil olmaqla bütün versiyalarında aşkar edilmiş kritik Remote Code Execution zəifliyidir. fetch_remote_file funksiyasında fayl adı doğrulama/təyinat uyğunsuzluğu səbəbilə autentifikasiya olunmamış hücumçu uzaqdan zərərli kod icra edə bilər. Plagindən istifadə edən saytların dərhal ən son təhlükəsizlik yeniləməsinə (3.7.2+) keçməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ1
Which WordPress plugin is affected by CVE-2026-18438?
CVE-2026-18438 affects all versions of the 'Templately – Elementor & Gutenberg Template Library' plugin, up to and including version 3.7.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.