Junglewise Threat Intelligence

CVE-2026-39563: ILLID Share This Image missing authorization in WordPress plugin

CVE-2026-39563 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

ILLID Share This Image, a WordPress plugin used to add social sharing buttons to website images, contains a security flaw in its access control settings. This vulnerability allows unauthorized individuals to bypass intended security levels, potentially leading to unauthorized changes or actions on the website. While the impact is considered moderate, it could allow attackers to interfere with how images are shared or managed on the platform.

Technical details

The vulnerability is classified as Missing Authorization (CWE-862) within the 'share-this-image' component of the ILLID Share This Image plugin. It stems from a failure to properly validate user permissions or security levels before allowing access to certain functions. An unauthenticated remote attacker can exploit this flaw to perform actions that should be restricted to higher-privileged users. The issue affects all versions up to and including 2.12; it was addressed in version 2.13. According to the CVSS vector, the primary impact is on integrity, though some assessments also suggest a potential for limited data disclosure.

Affected products

  • ILLID Share This Image <= 2.12

Timeline

  • 2026-02-24: other: Vulnerability reported by researcher
  • 2026-03-26: advisory: Patchstack advisory published
  • 2026-04-08: disclosed: CVE published to NVD
  • 2026-04-08: patched: Vulnerability fixed in version 2.13

References