CVE-2026-39526 is an Authorization Bypass Through User-Controlled Key vulnerability affecting WpStream plugin versions prior to 4.11.2. The flaw stems from incorrectly configured access control security levels that can be exploited by authenticated users to bypass authorization mechanisms. The vulnerability carries a CVSS score of 5.4 (Medium severity) with a network-based attack vector requiring low complexity and user authentication. While confidentiality is not impacted, successful exploitation could result in integrity and availability impacts, allowing attackers to modify data or cause service disruption. There is currently no evidence of active exploitation in the wild, as indicated by the absence of this CVE from the Known Exploited Vulnerabilities catalog and its inactive status on threat hotlists. The EPSS score of 0.0004 suggests minimal probability of exploitation attempts, indicating low community and attacker attention at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 4.11.2CPE match | cpe:2.3:a:wpstream:wpstream:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.