CVE-2026-39619: WordPress Busiprof theme <= 2.5.2 - Cross Site Request Forgery (CSRF) to Arbitrary File Upload vulnerability
Published Apr 8, 2026
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Busiprof busiprof allows Upload a Web Shell to a Web Server.This issue affects Busiprof: from n/a through <= 2.5.2.
Affected Software
1 affected component
priyanshumittal Busiprof<=2.5.2
Event History
Apr 8, 2026
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-39619?
CVE-2026-39619 has a critical severity rating of 9.6 according to the CVSS v3.1 scoring system.
2
How do I fix CVE-2026-39619?
To fix CVE-2026-39619, update the Busiprof theme to version 2.5.3 or later to mitigate the vulnerability.
3
What type of vulnerability is CVE-2026-39619?
CVE-2026-39619 is a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to upload arbitrary files.
4
Which software is affected by CVE-2026-39619?
CVE-2026-39619 affects the Busiprof theme developed by priyanshumittal versions 2.5.2 and prior.
5
What can attackers do with CVE-2026-39619?
Attackers can exploit CVE-2026-39619 to upload a web shell to the web server, potentially leading to a complete server compromise.