CVE-2026-39593: WordPress HAPPY plugin <= 1.0.10 - Broken Access Control vulnerability
Missing Authorization vulnerability in VillaTheme HAPPY allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects HAPPY: from n/a through 1.0.10.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress HAPPY Pluginto a version that resolves this vulnerability.Fixed in 1.0.11
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39593?
CVE-2026-39593 has a medium severity score of 6.5.
What vulnerability does CVE-2026-39593 present?
CVE-2026-39593 presents a Broken Access Control vulnerability due to missing authorization in the VillaTheme HAPPY plugin.
How do I fix CVE-2026-39593?
To fix CVE-2026-39593, update the WordPress HAPPY plugin to the latest available version, at least 1.0.11.
Which versions of the VillaTheme HAPPY plugin are affected by CVE-2026-39593?
CVE-2026-39593 affects VillaTheme HAPPY plugin versions from n/a through 1.0.10.
What can happen if CVE-2026-39593 is exploited?
If CVE-2026-39593 is exploited, it may allow attackers to circumvent access control security measures and gain unauthorized access.