CVE-2026-39640: WordPress Theme Editor plugin <= 3.2 - Cross Site Request Forgery (CSRF) to Remote Code Execution vulnerability
Published Apr 8, 2026
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor theme-editor allows Code Injection.This issue affects Theme Editor: from n/a through <= 3.2.
Affected Software
1 affected component
Mndpsingh287 Theme Editor<=3.2
Event History
Apr 8, 2026
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-39640?
CVE-2026-39640 is considered a critical severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2026-39640?
To fix CVE-2026-39640, update the mndpsingh287 Theme Editor plugin to a version higher than 3.2.
3
What type of vulnerability is CVE-2026-39640?
CVE-2026-39640 is a Cross Site Request Forgery (CSRF) vulnerability that can lead to Code Injection.
4
Who is affected by CVE-2026-39640?
CVE-2026-39640 affects users of the mndpsingh287 Theme Editor plugin version 3.2 and below.
5
What can attackers do with CVE-2026-39640?
Attackers can exploit CVE-2026-39640 to perform unauthorized actions that may lead to remote code execution.