What is CVE-2026-32474?
CVE-2026-32474 is an arbitrary file upload vulnerability in Templatiq plugin versions <= 0.2.5, exploitable by users with Contributor role. This can lead to remote code execution on the server. Immediate update to the latest version is recommended.
Azərbaycanca: CVE-2026-32474, Templatiq plaginin 0.2.5 və əvvəlki versiyalarında Contributor roluna malik istifadəçilərə ixtiyari fayl yükləməyə imkan verən boşluqdur. Bu zəiflikdən istifadə edərək hücum edənlər serverdə kod icrası həyata keçirə bilər. Plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
Which plugin is affected by CVE-2026-32474, and what is the nature of the vulnerability?
CVE-2026-32474 exists in Templatiq plugin versions <= 0.2.5. It is a vulnerability that allows users with the Contributor role to upload arbitrary files.
What can happen if CVE-2026-32474 is successfully exploited?
Exploiting this vulnerability can lead to remote code execution on the server.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.