CVE-2026-39659: WordPress Ultimate Member plugin <= 2.11.3 - Broken Access Control vulnerability
Published Apr 8, 2026
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
Ultimate Member Ultimate Member<=2.11.3
Event History
Apr 8, 2026
CVE Published
via MITRE·08:30 AM
Rejected
via MITRE·08:30 AM
Data Sourced
via NVD·09:16 AM
Description
Apr 21, 2026
Rejected
via MITRE·10:53 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-39659?
CVE-2026-39659 was identified as a broken access control vulnerability in the Ultimate Member plugin for WordPress.
2
How do I fix CVE-2026-39659?
Since CVE-2026-39659 has been rejected, there is no specific fix required for this vulnerability.
3
Is my site affected by CVE-2026-39659?
Only installations of the Ultimate Member plugin version 2.11.3 or lower were potentially affected by CVE-2026-39659.
4
What should I do to secure my WordPress site against broken access control issues like CVE-2026-39659?
Regularly update your WordPress plugins to the latest versions to mitigate broken access control risks.
5
What is the status of CVE-2026-39659?
CVE-2026-39659 has been rejected or withdrawn by its CVE Numbering Authority.