CVE-2026-39638 is a stored cross-site scripting (XSS) vulnerability in Themeum's Qubely plugin affecting versions 1.8.14 and earlier. The flaw stems from improper input neutralization during web page generation, allowing attackers to inject malicious scripts that persist in the application. This vulnerability impacts WordPress sites using the vulnerable Qubely versions. The vulnerability carries a CVSS score of 5.9 (MEDIUM severity) with a network-based attack vector requiring low complexity and high privileges plus user interaction to exploit. Successful exploitation could result in limited compromise of confidentiality, integrity, and availability across multiple security domains. There is no current evidence of active exploitation, with the EPSS score of 0.00033 indicating minimal real-world exploitation probability. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog and remains inactive on security hotlists. The FAUCET Risk Score of 34.0/100 suggests this is a lower-priority vulnerability with limited community attention, though organizations running affected Qubely versions should apply available patches to maintain security posture.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 1.8.14CPE match | cpe:2.3:a:themeum:qubely:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.