PatchSiren cyber security CVE debrief
CVE-2026-39691 AdAstraCrypto CVE debrief
A Missing Authorization vulnerability in AdAstraCrypto Cryptocurrency Donation Box – Bitcoin & Crypto Donations allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Cryptocurrency Donation Box – Bitcoin & Crypto Donations: from n/a through <= 2.2.13. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Users of the plugin should verify their installation and update to a patched version if necessary.
- Vendor
- AdAstraCrypto
- Product
- Cryptocurrency Donation Box – Bitcoin & Crypto Donations
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
Users of Cryptocurrency Donation Box – Bitcoin & Crypto Donations plugin for WordPress should verify their installation and update to a patched version if necessary. Additionally, security teams and vulnerability management teams should review the vulnerability and assess their exposure.
Technical summary
The CVE-2026-39691 vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. It is caused by a Missing Authorization issue in the AdAstraCrypto Cryptocurrency Donation Box – Bitcoin & Crypto Donations plugin. The vulnerability allows for Exploiting Incorrectly Configured Access Control Security Levels. The affected product is Cryptocurrency Donation Box – Bitcoin & Crypto Donations, and the vulnerability affects versions from n/a through <= 2.2.13.
Defensive priority
Medium priority due to the potential for unauthorized access.
Recommended defensive actions
- Verify the installed version of Cryptocurrency Donation Box – Bitcoin & Crypto Donations and update to a patched version if necessary.
- Implement additional monitoring and logging to detect potential exploitation attempts.
- Review and adjust access control configurations to prevent exploitation of incorrectly configured security levels.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record was published on 2026-04-08T09:16:41.370Z and has not been modified since. The NVD entry is currently Deferred. There is limited evidence available about the vulnerability, and defenders should verify the affected product deployments and review the official advisory for more information. The Cryptocurrency Donation Box – Bitcoin & Crypto Donations plugin for WordPress has a Missing Authorization vulnerability, which allows for Exploiting Incorrectly Configured Access Control Security Levels.
Official resources
-
CVE-2026-39691 CVE record
CVE.org
-
CVE-2026-39691 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T09:16:41.370Z and has not been modified since. The NVD entry is currently Deferred.