Junglewise Threat Intelligence

CVE-2026-39612: kutethemes KuteShop missing authorization in WordPress theme

CVE-2026-39612 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Vendors: KuteThemes.

Executive brief

KuteShop is a WordPress theme used to build e-commerce websites. A security flaw in the theme allows unauthorized individuals to bypass access controls, potentially leading to the execution of restricted commands or access to internal site features. This could allow an attacker to interfere with site operations or view information they should not have access to.

Technical details

A Missing Authorization (CWE-862) vulnerability exists in the KuteShop theme for WordPress through version 4.2.9. The flaw stems from a failure to implement proper authorization checks or nonce validation on certain functions, which can lead to arbitrary shortcode execution. An unauthenticated remote attacker can exploit this by sending crafted requests to the site, potentially allowing them to execute actions that should be restricted to higher-privileged users. As of the latest advisory, no official patch has been released.

Affected products

  • kutethemes KuteShop <= 4.2.9

Timeline

  • 2026-01-10: other: Vulnerability reported by researcher João Pedro S Alcântara
  • 2026-02-09: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: CVE published in NVD

References

Related threats