Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39528

21
FAUCET Score

CVE-2026-39528 is a missing authorization vulnerability in the WP Delicious plugin for WordPress (versions through 1.9.5) that stems from incorrectly configured access control security levels in the delicious-recipes component. This flaw allows unauthorized users to bypass authentication controls and gain unauthorized access to sensitive functionality. The vulnerability carries a CVSS 3.1 score of 5.3 (Medium severity) with a network-based attack vector that requires no special privileges or user interaction. The attack has low complexity, meaning a threat actor with basic technical knowledge could exploit it. The primary impact is limited to confidentiality breach, with no integrity or availability impacts noted. There is currently no evidence of active exploitation in the wild, as the vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and carries an extremely low EPSS score of 0.00037. The low FAUCET risk score of 32.0 and inactive status on threat tracking lists suggest minimal community attention and exploit availability at this time.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0, <= 1.9.5CPE match
cpe:2.3:a:wpdelicious:wp_delicious:*:*:*:*:*:wordpress:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.23%
Probability of exploitation in next 30 days
EPSS Percentile
13.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0023 is in the 5th percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

patchstack.com / database/Wordpress/Plugin/delicious-recipes/vulnerability/wordpress-wp-delicious-plugin-1-9-5-broken-access-control-vulnerability