CVE-2026-39620: WordPress Appointment theme <= 3.5.5 - Cross Site Request Forgery (CSRF) to Arbitrary File Upload vulnerability
Published Apr 8, 2026
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment appointment allows Upload a Web Shell to a Web Server.This issue affects Appointment: from n/a through <= 3.5.5.
Affected Software
1 affected component
priyanshumittal Appointment (WordPress theme)<=3.5.5
Event History
Apr 8, 2026
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-39620?
CVE-2026-39620 has a critical severity rating of 9.6 according to CVSS 3.1.
2
What is the impact of CVE-2026-39620?
CVE-2026-39620 allows attackers to exploit a Cross-Site Request Forgery (CSRF) vulnerability to upload arbitrary files to the web server.
3
How do I fix CVE-2026-39620?
To mitigate CVE-2026-39620, update the Appointment theme to version 3.5.6 or higher.
4
Which versions of the Appointment theme are affected by CVE-2026-39620?
CVE-2026-39620 affects the Appointment theme in versions n/a through 3.5.5.
5
What kind of attack is CVE-2026-39620 associated with?
CVE-2026-39620 is associated with a Cross-Site Request Forgery (CSRF) attack leading to arbitrary file uploads.