Arbitrary Content Deletion in WPAMS Plugin by WordPress
CVE-2026-39433

6.5MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
16 June 2026

What is CVE-2026-39433?

The WPAMS plugin for WordPress contains a vulnerability that allows subscribers to delete arbitrary content, potentially leading to data loss or service disruption. Versions prior to 49.5.3 are affected, and users are strongly advised to update to the latest version to mitigate this risk. This issue highlights the importance of maintaining updated plugins to ensure the security and integrity of WordPress websites.

Affected Version(s)

WPAMS < 49.5.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Denver Jackson | Patchstack Bug Bounty Program
.