MEDIUM
shrikantkale
CVE published 2026-04-08
CVE-2026-39673
A Missing Authorization vulnerability in shrikantkale iZooto izooto-web-push allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects iZooto: from n/a through <= 3.7.20. The CVSS score is 5.3, and the severity is MEDIUM. Users of iZooto izooto-web-push plugin for WordPress should verify their version and update to a patched version if necessary. The vulnerability allows [truncated]