PatchSiren

mndpsingh287 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL mndpsingh287 CVE published 2026-04-08

CVE-2026-39640

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the Theme Editor plugin, which could allow for code injection. The issue affects Theme Editor versions from n/a through 3.2. Administrators and users should be aware of this vulnerability and take necessary precautions. This vulnerability has a CVSS score of 9.6 and is classified as CRITICAL.