External risk intelligence

YAHMAN Add-ons WordPress Plugin Arbitrary File Write Leading to RCE.

CVE advisorySeverity: CRITICAL (CVSS 9.0)

CVE-2026-75799

The vulnerability affects a WordPress plugin, which is typically deployed as part of a public-facing web application. Since the plugin's functionality involves caching files in a publicly accessible directory and is reachable via the web, it is commonly exposed to the internet in standard WordPress deployments.

Code Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability in a WordPress plugin allows attackers to place malicious files on servers, potentially leading to unauthorized control if the plugin's caching feature is active. The main concern is confirming relevance and exposure, as the threat depends on specific plugin configurations.

  • Attackers can upload malicious code.
  • Affects public-facing websites with specific configurations.
  • Confirm relevance and exposure for high-risk systems.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by uploading a malicious PHP file to a publicly accessible directory on the server, without needing any prior authentication. If the vulnerable feature within the YAHMAN Add-ons WordPress plugin is active, the server might cache this file. Subsequently, accessing the cached file could lead to the execution of arbitrary code on the server.

  • Unauthenticated network access required.
  • Caching of uploaded PHP files.
  • Arbitrary code execution on server.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to execute arbitrary PHP code on the server if the plugin's caching feature is enabled. This could occur when the plugin processes remote files, and an attacker crafts a malicious PHP file to be cached.

  • Arbitrary PHP file write on server.
  • Unauthenticated remote file caching.
  • Remote code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

The YAHMAN Add-ons WordPress plugin's vulnerability requires prompt attention from the application owner responsible for the WordPress environment. The initial step is to confirm the presence of this plugin within the environment, determine its reachability and business criticality, and then assign ownership for remediation.

  • Application owners should manage this issue.
  • Verify plugin presence and exposure.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the YAHMAN Add-ons plugin?

YAHMAN Add-ons is a software extension for WordPress websites. Plugins like this are typically installed to add specialized features or enhanced functionality to the core platform, such as custom content management tools or expanded site performance options. Users choose this specific plugin to extend their WordPress site's capabilities, though it introduces its own code and potential security dependencies into the server environment.

How does CVE-2026-75799 allow arbitrary code execution?

This vulnerability is classified as Improper Control of Generation of Code (CWE-94). It occurs because the plugin fails to check the file type of remote data it caches. An attacker can use this weakness to trick the plugin into saving a malicious PHP script into a public folder on your server. Because the server treats this saved file as executable code rather than simple data, the attacker can force the system to run their unauthorized commands.

Do I need the plugin's caching feature enabled to be at risk?

Yes. The vulnerability specifically relies on the plugin's file caching mechanism to save the malicious script to the server. If this specific feature is disabled or not in use, the path for the attacker to place the harmful file is blocked. Simply having the plugin installed is not enough; the vulnerable functionality must be active for the exploit to succeed.

Is my website at risk if it uses YAHMAN Add-ons?

According to Halo Surface Signal, this vulnerability is highly relevant because the plugin is commonly used in public-facing WordPress environments. Since the plugin caches files in directories that are reachable via the internet, a server running this technology is often exposed to remote attackers. You should consider your site at higher risk if it is accessible to the public and the plugin's caching features are active.

When should I take action for CVE-2026-75799?

You should prioritize this immediately if you use the YAHMAN Add-ons plugin. Start by checking your WordPress site's plugin list to confirm if this software is installed. If it is, verify whether the caching feature is currently turned on. Once you have identified the systems running the plugin, assign an owner to manage the situation and plan for updates or configuration changes to remove the risk.

References