PatchSiren cyber security CVE debrief
CVE-2026-39668 g5theme CVE debrief
A Missing Authorization vulnerability exists in g5theme Book Previewer for Woocommerce, affecting versions from n/a through <= 1.0.6. This issue is related to Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Users of Book Previewer for Woocommerce plugin, especially those using versions from n/a through <= 1.0.6, should be aware of this vulnerability and take necessary actions to secure their installations. The vulnerability allows unauthorized access due to incorrectly configured access control security levels. To address this, review and adjust access control configurations for the plugin and monitor for any suspicious activity related to the plugin.
- Vendor
- g5theme
- Product
- Book Previewer for Woocommerce
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
Users of Book Previewer for Woocommerce plugin, especially those using versions from n/a through <= 1.0.6, should be aware of this vulnerability and take necessary actions to secure their installations.
Technical summary
The CVE-2026-39668 vulnerability is a Missing Authorization issue in the Book Previewer for Woocommerce plugin. It allows unauthorized access due to incorrectly configured access control security levels. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 5.3, indicating a medium severity level. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. The vulnerability affects Book Previewer for Woocommerce versions from n/a through <= 1.0.6. To mitigate, update the plugin to the latest version and review access control configurations.
Defensive priority
Medium priority should be given to updating the Book Previewer for Woocommerce plugin to a version that fixes this vulnerability. Additionally, review and adjust access control configurations for the plugin and monitor for any suspicious activity related to the plugin. Consider compensating controls for exposed systems while remediation is scheduled and verified. Track exceptions, retest remediated assets, and close the item only after evidence is documented. Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Check relevant monitoring, detection, and logs for exposed assets that need extra review. This vulnerability allows unauthorized access due to incorrectly configured access control security levels, with a CVSS score of 5.3 and a severity of MEDIUM. Users of Book Previewer for Woocommerce plugin, especially those using versions from n/a through <= 1.0.6, should be aware of this vulnerability and take necessary actions to secure their installations. The Common Vulnerability Scoring System (CVSS) vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. A Missing Authorization vulnerability exists in g5theme Book Previewer for Woocommerce, affecting versions from n/a through <= 1.0.6. This issue is related to Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Users of Book Previewer for Woocommerce plugin, especially those using versions from n/a through <= 1.0.6, should be aware of this vulnerability and take necessary actions to secure their installations. The CVE-2026-39668 vulnerability is a Missing Authorization issue in the Book Previewer for Woocommerce plugin. It allows unauthorized access due to incorrectly configured access control security levels. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 5.3, indicating a medium severity level. The CVSS vector is CVSS:3.1/AV:N/AC:
Recommended defensive actions
- Update Book Previewer for Woocommerce plugin to the latest version
- Review and adjust access control configurations for the plugin
- Monitor for any suspicious activity related to the plugin
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record was published on 2026-04-08T09:16:38.170Z and has not been modified since then. The NVD entry is currently deferred. Patchstack has provided a mitigation reference for this vulnerability. Evidence is limited, and defenders should verify affected scope and vendor guidance. The vulnerability affects Book Previewer for Woocommerce versions from n/a through <= 1.0.6.
Official resources
-
CVE-2026-39668 CVE record
CVE.org
-
CVE-2026-39668 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T09:16:38.170Z and has not been modified since then. The NVD entry is currently deferred.