The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE when the relevant feature is enabled.
Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.