CRITICAL
mndpsingh287
CVE published 2026-04-08
CVE-2026-39640
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the Theme Editor plugin, which could allow for code injection. The issue affects Theme Editor versions from n/a through 3.2. Administrators and users should be aware of this vulnerability and take necessary precautions. This vulnerability has a CVSS score of 9.6 and is classified as CRITICAL.