CVE-2026-18438: Templately <= 3.7.1 - Authenticated (Contributor+) Arbitrary File Upload to Remote Code Execution via Gutenberg Cloud Import Attachment Filename Mismatch

Published Aug 15, 2026
·
Updated

The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.7.1 via the fetchremotefile function. This is due to a filename validation/destination mismatch in fetchremotefile, where file type validation is performed against the attacker-controlled Content-Disposition filename rather than the URL-path-derived destination filename. This makes it possible for authenticated attackers, with contributor-level access and above, to execute code on the server. A GIF+PHP polyglot file passes wpcheckfiletypeandext validation as image/gif via the Content-Disposition filename, while the actual destination path is written with a .php extension derived from the URL path, bypassing the unfilteredupload capability gate entirely. The affected endpoints are reachable at this privilege level because Templately's entire REST API — including the cloud import endpoints used in this attack (/templately/v1/clouds/upload and /templately/v1/insert) — is authorized only by a currentusercan('deleteposts') check, with no administrator or manageoptions capability requirement. The same permission gate also allows a contributor to overwrite the site's global Templately cloud connection via the /templately/v1/login endpoint with globalsignin set to true. A complete remediation should both correct fetchremotefile to validate the file type against the actual destination filename rather than the Content-Disposition header (and avoid deriving the write path from the request URL), and restrict state-changing Templately REST routes to an appropriate administrator-level capability.

Affected Software

1 affected component
Templately – Elementor & Gutenberg Template Library for WordPress<=3.7.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Templately to a version that resolves this vulnerability.

    Fixed in 3.7.1
  2. Configuration

    Change the authorization check used for Templately’s cloud import and login REST endpoints so that state-changing routes (notably /templately/v1/clouds/upload and /templately/v1/insert) require an administrator-level capability (instead of only current_user_can('delete_posts'), which currently allows Contributor+ access).

    Templately REST API endpoints (/templately/v1/clouds/upload, /templately/v1/insert, /templately/v1/login) capability gate (current_user_can('delete_posts')) = delete_posts -> administrator-level capability
  3. Configuration

    Fix fetch_remote_file so file type validation is performed against the actual destination filename/extension used for the write (the .php-derived destination filename logic), rather than the attacker-controlled Content-Disposition header filename.

    Templately fetch_remote_file remote file type validation source (Content-Disposition vs destination filename) = validate against actual destination filename not Content-Disposition filename
  4. Configuration

    Update fetch_remote_file to avoid deriving the write destination path/filename from the request URL path; the destination filename should not be influenced by the attacker-controlled URL so the type validation and write destination match.

    Templately fetch_remote_file write-path derivation = do not derive write destination path from request URL path

Event History

Aug 15, 2026
CVE Published
via MITRE·09:25 AM
Data Sourced
via MITRE·09:25 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203