CVE-2026-39716 is a missing authorization vulnerability affecting CKThemes Flipmart versions 2.8 and earlier, stemming from incorrectly configured access control security levels that allow unauthorized access to sensitive functions. The vulnerability has a CVSS score of 5.3 (medium severity) with a network-based attack vector requiring no authentication or user interaction, making it relatively easy to exploit. The primary impact is limited to confidentiality, as the vulnerability enables low-level information disclosure without affecting system integrity or availability. There is currently no evidence of active exploitation in the wild, with an EPSS score of 0.000370 indicating minimal real-world exploitation probability at this time. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog and remains inactive on security hotlists, suggesting community attention has been minimal thus far.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| CKThemes | Flipmart | >= 0, <= 2.8CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.