CVE-2026-39640 is a Cross-Site Request Forgery vulnerability in the mndpsingh287 Theme Editor WordPress theme (versions 3.2 and earlier) that enables code injection attacks. The flaw allows unauthenticated attackers to exploit social engineering tactics to execute arbitrary code within affected installations. The vulnerability carries a CRITICAL severity rating (CVSS 9.6) with a network-based attack vector requiring minimal complexity and user interaction, but potentially compromising confidentiality, integrity, and availability across system boundaries. The exposure is particularly concerning due to the absence of authentication requirements. Current exploitation status indicates no active real-world exploitation documented in known exploit databases or vulnerability tracking lists. The EPSS score of 0.000190000 suggests minimal probability of exploitation in the near term, and the vulnerability remains inactive on threat intelligence hotlists, indicating limited community attention and threat actor interest at this time. However, the critical CVSS rating warrants prompt patching before widespread awareness develops.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Mndpsingh287 | Theme Editor | >= 0, <= 3.2CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.