HIGH
spicethemes
CVE published 2026-04-08
CVE-2026-39621
A high-severity Cross-Site Request Forgery (CSRF) vulnerability was discovered in the SpicePress theme, affecting versions from n/a through 2.3.2.5. This issue allows attackers to upload a web shell to a web server, potentially leading to arbitrary plugin installation. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. It is tracked under CWE-352. Administrators and users of the [truncated]