CVE-2026-39571: WordPress Instantio plugin <= 3.3.30 - Sensitive Data Exposure vulnerability
Published Apr 8, 2026
·Updated
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Themefic Instantio instantio allows Retrieve Embedded Sensitive Data.This issue affects Instantio: from n/a through <= 3.3.30.
Affected Software
1 affected component
Themefic Instantio<=3.3.30
Event History
Apr 8, 2026
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-39571?
The severity of CVE-2026-39571 is classified as medium with a CVSS score of 5.3.
2
How do I fix CVE-2026-39571?
To fix CVE-2026-39571, update the Themefic Instantio plugin to a version greater than 3.3.30.
3
What information is exposed in CVE-2026-39571?
CVE-2026-39571 exposes sensitive system information embedded within the Instantio plugin.
4
Which versions of Themefic Instantio are affected by CVE-2026-39571?
CVE-2026-39571 affects Themefic Instantio versions from n/a through 3.3.30.
5
Is CVE-2026-39571 a critical vulnerability?
CVE-2026-39571 is not considered critical but is classified as a medium severity vulnerability.