CVE-2026-39701 is a Missing Authorization vulnerability affecting Andrew ShopWP wpshopify plugin versions up to and including 5.2.4. The flaw stems from incorrectly configured access control security levels that allow unauthorized exploitation. This vulnerability in the popular WordPress plugin could expose systems to unauthorized modification of data or settings. The vulnerability has a CVSS score of 5.3 (Medium severity) and can be exploited remotely over the network without requiring authentication, special privileges, or user interaction. While the attack complexity is low, the impact is limited to integrity compromises with no confidentiality or availability impact. The EPSS score of 0.00037 indicates relatively low prevalence compared to other known vulnerabilities. There is currently no evidence of active exploitation in the wild, as the vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat intelligence hot lists. However, organizations running vulnerable versions of wpshopify should prioritize patching to versions above 5.2.4 to mitigate unauthorized access control risks, particularly if they process sensitive customer or transactional data.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Andrew | ShopWP | >= 0, <= 5.2.4CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.