CSRF Vulnerability in Theme Editor Plugin by WordPress
CVE-2026-39640

9.6CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
8 April 2026

What is CVE-2026-39640?

The Theme Editor plugin for WordPress contains a cross-site request forgery (CSRF) vulnerability that could allow attackers to inject malicious code. This security flaw affects versions up to and including 3.2, enabling remote code execution due to improper validation. Users are urged to update their plugins to mitigate potential threats and safeguard their websites from exploitation.

Affected Version(s)

Theme Editor 0 <= 3.2

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hhhai | Patchstack Bug Bounty Program
.