CVE-2023-5454: Templately
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, allowing unauthenticated users to delete arbitrary posts.
Affected products
- Templately Templately: before 2.2.6 (fixed in 2.2.6)
Published 2023-11-06. Last modified 2026-06-17.