cvedb.io
CVE-2026-15359
MEDIUM · CVSS 6.5
EPSS exploitation probability: 0%
Published 2026-08-07T06:16:55.460 · Last modified 2026-08-07T18:17:08.650

Summary

The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allowing unauthenticated attackers to overwrite the administrator's stored cloud service connection with an account under their control, disconnecting the legitimate administrator and redirecting the site's cloud template library to attacker-controlled content.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.