Junglewise Threat Intelligence

CVE-2026-39589: A WP Life Webenvo arbitrary file upload in WordPress theme

CVE-2026-39589 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Executive brief

Webenvo is a theme used to design and layout WordPress websites. A security flaw in this theme allows users with basic 'Subscriber' accounts to upload malicious files to the web server. This could allow an attacker to gain full control over the website, steal sensitive data, or cause a complete service outage.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in the A WP Life Webenvo theme for WordPress in versions up to and including 0.0.6. The flaw allows authenticated users with Subscriber-level permissions to upload dangerous file types, such as PHP scripts, to the server. Because the application fails to properly validate file extensions or content, an attacker can achieve remote code execution (RCE) and potentially gain full system access. The vulnerability is addressed in version 0.0.7.

Affected products

  • A WP Life Webenvo <= 0.0.6

Timeline

  • 2026-02-22: other: Vulnerability reported by Denver Jackson
  • 2026-04-20: advisory: Initial advisory published by Patchstack
  • 2026-06-17: disclosed: CVE published to NVD

References