Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39640

31
FAUCET Score

CVE-2026-39640 is a Cross-Site Request Forgery vulnerability in the mndpsingh287 Theme Editor WordPress theme (versions 3.2 and earlier) that enables code injection attacks. The flaw allows unauthenticated attackers to exploit social engineering tactics to execute arbitrary code within affected installations. The vulnerability carries a CRITICAL severity rating (CVSS 9.6) with a network-based attack vector requiring minimal complexity and user interaction, but potentially compromising confidentiality, integrity, and availability across system boundaries. The exposure is particularly concerning due to the absence of authentication requirements. Current exploitation status indicates no active real-world exploitation documented in known exploit databases or vulnerability tracking lists. The EPSS score of 0.000190000 suggests minimal probability of exploitation in the near term, and the vulnerability remains inactive on threat intelligence hotlists, indicating limited community attention and threat actor interest at this time. However, the critical CVSS rating warrants prompt patching before widespread awareness develops.

Impacted Technologies

VendorProductVersion(s)CPE
Mndpsingh287Theme Editor
>= 0, <= 3.2CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

9.6CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.14%
Probability of exploitation in next 30 days
EPSS Percentile
4.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0014 is in the 0th percentile among its peer group of 836 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

patchstack.com / database/Wordpress/Plugin/theme-editor/vulnerability/wordpress-theme-editor-plugin-3-2-cross-site-request-forgery-csrf-to-remote-code-execution-vulnerability