PatchSiren

spicethemes CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH spicethemes CVE published 2026-04-08

CVE-2026-39621

A high-severity Cross-Site Request Forgery (CSRF) vulnerability was discovered in the SpicePress theme, affecting versions from n/a through 2.3.2.5. This issue allows attackers to upload a web shell to a web server, potentially leading to arbitrary plugin installation. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity. It is tracked under CWE-352. Administrators and users of the [truncated]