CSRF Vulnerability in Theme Editor Plugin by WordPress
CVE-2026-39640
9.6CRITICAL
What is CVE-2026-39640?
The Theme Editor plugin for WordPress contains a cross-site request forgery (CSRF) vulnerability that could allow attackers to inject malicious code. This security flaw affects versions up to and including 3.2, enabling remote code execution due to improper validation. Users are urged to update their plugins to mitigate potential threats and safeguard their websites from exploitation.
Affected Version(s)
Theme Editor 0 <= 3.2