PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-39673 shrikantkale CVE debrief

A Missing Authorization vulnerability in shrikantkale iZooto izooto-web-push allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects iZooto: from n/a through <= 3.7.20. The CVSS score is 5.3, and the severity is MEDIUM. Users of iZooto izooto-web-push plugin for WordPress should verify their version and update to a patched version if necessary. The vulnerability allows attackers to exploit incorrectly configured access control security levels. The Common Vulnerability Scoring System (CVSS) vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N.

Vendor
shrikantkale
Product
iZooto
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-24
Advisory published
2026-04-08
Advisory updated
2026-07-24

Who should care

Users of iZooto izooto-web-push plugin for WordPress should verify their version and update to a patched version if necessary. This includes administrators and security teams responsible for maintaining WordPress installations with the iZooto izooto-web-push plugin. Additionally, operators and platform managers should review the vulnerability's impact on their systems and take necessary actions.

Technical summary

The iZooto izooto-web-push plugin for WordPress has a Missing Authorization vulnerability. This vulnerability allows attackers to exploit incorrectly configured access control security levels. The issue affects iZooto versions from n/a through 3.7.20. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 5.3, indicating a MEDIUM severity level. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N.

Defensive priority

Medium priority should be given to updating the iZooto izooto-web-push plugin to a version that addresses this vulnerability.

Recommended defensive actions

  • Verify the version of iZooto izooto-web-push plugin installed and update to a patched version if necessary.
  • Review and adjust access control configurations for the plugin to ensure proper authorization.
  • Monitor for any suspicious activity related to the plugin.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.

Evidence notes

The CVE record was published on 2026-04-08T09:16:38.827Z and has not been modified since. The NVD entry is currently Deferred. The vulnerability was reported by [email protected]. The source item URL for CVE-2026-39673 is provided, but additional verification is recommended due to limited source detail.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T09:16:38.827Z and has not been modified since. The NVD entry is currently Deferred.