CVE-2026-39627: WordPress Ashe theme <= 2.266 - Broken Access Control vulnerability
Published Apr 8, 2026
·Updated
Missing Authorization vulnerability in wproyal Ashe ashe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ashe: from n/a through <= 2.266.
Affected Software
1 affected component
wpRoyal Ashe WordPress theme<=2.266
Event History
Apr 8, 2026
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-39627?
The severity of CVE-2026-39627 is considered critical due to the risk of unauthorized access to sensitive data.
2
How do I fix CVE-2026-39627?
To fix CVE-2026-39627, update the Ashe theme to the latest version available beyond 2.266.
3
What kind of vulnerability is CVE-2026-39627?
CVE-2026-39627 is a Broken Access Control vulnerability that allows attackers to exploit improperly configured access security levels.
4
Which versions of the Ashe theme are affected by CVE-2026-39627?
The vulnerability affects all versions of the Ashe theme from n/a through version 2.266.
5
Is authentication required to exploit CVE-2026-39627?
No authentication is required to exploit CVE-2026-39627, allowing unauthenticated users to access restricted data.