Junglewise Threat Intelligence

CVE-2026-39610: Pankaj Kumar WpXmas-Snow missing authorization in WordPress plugin

CVE-2026-39610 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

WpXmas-Snow is a WordPress plugin used to add seasonal visual effects to websites. A security flaw in this plugin allows unauthorized individuals to bypass access controls and potentially modify settings or perform actions that should be restricted to site administrators. While the impact is considered low, it could allow an attacker to interfere with the plugin's functionality or site appearance.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Pankaj Kumar WpXmas-Snow plugin for WordPress in versions up to and including 1.1. The vulnerability stems from a failure to implement proper access control checks or nonce validation on certain functions. An unauthenticated remote attacker can exploit this to perform actions that should be restricted to higher-privileged users. The issue is resolved in version 1.2.

Affected products

  • Pankaj Kumar WpXmas-Snow <= 1.1

Timeline

  • 2026-01-08: other: Reported by researcher Legion Hunter
  • 2026-02-07: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: CVE published

References