CVE-2026-32474: WordPress Templatiq plugin <= 0.2.5 - Arbitrary File Upload vulnerability
Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Templatiq pluginto a version that resolves this vulnerability.Fixed in 0.2.5
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
WordPress sites running Templatiq version 0.2.5 or earlier are affected. Exploitation requires Contributor-level access, so unauthenticated visitors are not identified as able to exploit this issue by the available data.
What access does an attacker need to exploit it?
An attacker needs a WordPress account with the Contributor role or equivalent Contributor-level permissions. No user interaction is required, and the attack can be performed over the network.
How can I determine whether my site is affected?
Identify sites where Templatiq is installed and determine whether the installed version is 0.2.5 or earlier. Review whether Contributor accounts exist, especially untrusted, compromised, or unnecessary accounts.