← back to popular plugins
wordfence / plugin · templately

Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud!

templately
total installs
400,000
total vulns
3
critical
0
high
0
medium
3
low
0
latest vuln
patched
3
unpatched
0
avg time to patch
vulnerabilities (3)
Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! <= 3.6.1 - Authenticated (Contributor+) Information Exposure
medium ✓ patched
cvss score 4.3
cwe CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
published Apr 27, 2026
The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.1. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive user or configuration data.
Templately <= 3.4.8 - Unauthenticated Limited Arbitrary JSON File Write
medium ✓ patched
cvss score 5.3
cwe CWE-863: Incorrect Authorization
published Jan 9, 2026
The Templately plugin for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 3.4.8. This is due to inadequate input validation in the `save_template_to_file()` function where user-controlled parameters like `session_id`, `content_id`, and `ai_page_ids` are used to construct file paths without proper sanitization. This makes it possible for unauthenticated attackers to write arbitrary `.ai.json` files to locations within the uploads directory.
Templately <= 3.2.7 - Authenticated (Author+) Information Disclosure
medium ✓ patched
cvss score 4.3
cwe CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
published Aug 20, 2025
The Templately – Elementor & Gutenberg Template Library: 5500+ Free & Pro Ready Templates And Cloud! plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.7. This makes it possible for authenticated attackers, with Author-level access and above, to extract sensitive user or configuration data.