CVE-2016-10995: Templatic Telvolution

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

The Tevolution plugin before 2.3.0 for WordPress has arbitrary file upload via single_upload.php or single-upload.php.

Affected products

  • Templatic Telvolution: before 2.3.0 (fixed in 2.3.0)

Published 2019-09-18. Last modified 2026-06-17.