MEDIUM
Pankaj Kumar
CVE published 2026-04-08
CVE-2026-39610
A Missing Authorization vulnerability was found in the WpXmas-Snow plugin. This issue allows for Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability affects WpXmas-Snow from n/a through version 1.1. Users of WpXmas-Snow plugin, especially those with version 1.1 or earlier, should be aware of this vulnerability and take necessary actions to secure their installations. The CV [truncated]