CVE-2026-18438: Templately <= 3.7.1 - Authenticated (Contributor+) Arbitrary File Upload to Remote Code Execution via Gutenberg Cloud Import Attachment Filename Mismatch
The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.7.1 via the fetchremotefile function. This is due to a filename validation/destination mismatch in fetchremotefile, where file type validation is performed against the attacker-controlled Content-Disposition filename rather than the URL-path-derived destination filename. This makes it possible for authenticated attackers, with contributor-level access and above, to execute code on the server. A GIF+PHP polyglot file passes wpcheckfiletypeandext validation as image/gif via the Content-Disposition filename, while the actual destination path is written with a .php extension derived from the URL path, bypassing the unfilteredupload capability gate entirely. The affected endpoints are reachable at this privilege level because Templately's entire REST API — including the cloud import endpoints used in this attack (/templately/v1/clouds/upload and /templately/v1/insert) — is authorized only by a currentusercan('deleteposts') check, with no administrator or manageoptions capability requirement. The same permission gate also allows a contributor to overwrite the site's global Templately cloud connection via the /templately/v1/login endpoint with globalsignin set to true. A complete remediation should both correct fetchremotefile to validate the file type against the actual destination filename rather than the Content-Disposition header (and avoid deriving the write path from the request URL), and restrict state-changing Templately REST routes to an appropriate administrator-level capability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Templatelyto a version that resolves this vulnerability.Fixed in 3.7.1 - Configuration
Change the authorization check used for Templately’s cloud import and login REST endpoints so that state-changing routes (notably /templately/v1/clouds/upload and /templately/v1/insert) require an administrator-level capability (instead of only current_user_can('delete_posts'), which currently allows Contributor+ access).
Templately REST API endpoints (/templately/v1/clouds/upload, /templately/v1/insert, /templately/v1/login) capability gate (current_user_can('delete_posts')) = delete_posts -> administrator-level capability - Configuration
Fix fetch_remote_file so file type validation is performed against the actual destination filename/extension used for the write (the .php-derived destination filename logic), rather than the attacker-controlled Content-Disposition header filename.
Templately fetch_remote_file remote file type validation source (Content-Disposition vs destination filename) = validate against actual destination filename not Content-Disposition filename - Configuration
Update fetch_remote_file to avoid deriving the write destination path/filename from the request URL path; the destination filename should not be influenced by the attacker-controlled URL so the type validation and write destination match.
Templately fetch_remote_file write-path derivation = do not derive write destination path from request URL path