Arbitrary Content Deletion in WPAMS Plugin by WordPress
CVE-2026-39433
6.5MEDIUM
What is CVE-2026-39433?
The WPAMS plugin for WordPress contains a vulnerability that allows subscribers to delete arbitrary content, potentially leading to data loss or service disruption. Versions prior to 49.5.3 are affected, and users are strongly advised to update to the latest version to mitigate this risk. This issue highlights the importance of maintaining updated plugins to ensure the security and integrity of WordPress websites.
Affected Version(s)
WPAMS < 49.5.3