CVE-2026-39637: WordPress Mogi theme <= 1.2.3 - Arbitrary Shortcode Execution vulnerability
Published Apr 8, 2026
·Updated
Missing Authorization vulnerability in SpabRice Mogi mogi allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mogi: from n/a through <= 1.2.3.
Affected Software
1 affected component
SpabRice Mogi WordPress theme<=1.2.3
Event History
Apr 8, 2026
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-39637?
The severity of CVE-2026-39637 is rated as medium with a score of 5.3.
2
How do I fix CVE-2026-39637?
To fix CVE-2026-39637, update the SpabRice Mogi WordPress theme to the latest version that remediates this vulnerability.
3
What type of vulnerability is CVE-2026-39637?
CVE-2026-39637 is classified as an arbitrary shortcode execution vulnerability due to missing authorization.
4
Which versions of the SpabRice Mogi theme are affected by CVE-2026-39637?
CVE-2026-39637 affects the SpabRice Mogi theme versions from n/a through version 1.2.3.
5
What could be the consequences of exploiting CVE-2026-39637?
Exploiting CVE-2026-39637 could allow unauthorized users to execute arbitrary shortcodes, potentially leading to further security breaches.