CVE-2026-0831

MEDIUM

Templately <3.4.8 - Arbitrary File Write

Title source: llm
STIX 2.1

Description

The Templately plugin for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 3.4.8. This is due to inadequate input validation in the `save_template_to_file()` function where user-controlled parameters like `session_id`, `content_id`, and `ai_page_ids` are used to construct file paths without proper sanitization. This makes it possible for unauthenticated attackers to write arbitrary `.ai.json` files to locations within the uploads directory.

Scores

CVSS v3 5.3
EPSS 0.0023
EPSS Percentile 13.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
wpdevteam/Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! < 3.4.8
Published Jan 10, 2026
Tracked Since Feb 18, 2026