PatchSiren cyber security CVE debrief
CVE-2026-39673 shrikantkale CVE debrief
A Missing Authorization vulnerability in shrikantkale iZooto izooto-web-push allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects iZooto: from n/a through <= 3.7.20. The CVSS score is 5.3, and the severity is MEDIUM. Users of iZooto izooto-web-push plugin for WordPress should verify their version and update to a patched version if necessary. The vulnerability allows attackers to exploit incorrectly configured access control security levels. The Common Vulnerability Scoring System (CVSS) vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N.
- Vendor
- shrikantkale
- Product
- iZooto
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
Users of iZooto izooto-web-push plugin for WordPress should verify their version and update to a patched version if necessary. This includes administrators and security teams responsible for maintaining WordPress installations with the iZooto izooto-web-push plugin. Additionally, operators and platform managers should review the vulnerability's impact on their systems and take necessary actions.
Technical summary
The iZooto izooto-web-push plugin for WordPress has a Missing Authorization vulnerability. This vulnerability allows attackers to exploit incorrectly configured access control security levels. The issue affects iZooto versions from n/a through 3.7.20. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 5.3, indicating a MEDIUM severity level. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N.
Defensive priority
Medium priority should be given to updating the iZooto izooto-web-push plugin to a version that addresses this vulnerability.
Recommended defensive actions
- Verify the version of iZooto izooto-web-push plugin installed and update to a patched version if necessary.
- Review and adjust access control configurations for the plugin to ensure proper authorization.
- Monitor for any suspicious activity related to the plugin.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
Evidence notes
The CVE record was published on 2026-04-08T09:16:38.827Z and has not been modified since. The NVD entry is currently Deferred. The vulnerability was reported by [email protected]. The source item URL for CVE-2026-39673 is provided, but additional verification is recommended due to limited source detail.
Official resources
-
CVE-2026-39673 CVE record
CVE.org
-
CVE-2026-39673 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T09:16:38.827Z and has not been modified since. The NVD entry is currently Deferred.