Junglewise Threat Intelligence

CVE-2026-39621: spicethemes SpicePress CSRF leading to Web Shell upload

CVE-2026-39621 · Severity: high · CVSS 8.8 · Published 2026-04-08

Executive brief

SpicePress, a theme for WordPress websites, contains a security flaw that could allow an attacker to take over a website. By tricking a site administrator into clicking a malicious link, an attacker can force the site to install unauthorized software or upload a 'web shell,' which provides full remote control over the server. This could lead to the theft of customer data, website defacement, or the complete shutdown of the site.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the spicethemes SpicePress theme for WordPress (versions up to and including 2.3.2.5). The flaw resides in a lack of nonce validation or insufficient request verification, which allows an attacker to craft a malicious request that, when executed by a logged-in administrator, triggers the installation of arbitrary plugins or the upload of a web shell. Successful exploitation grants the attacker remote code execution (RCE) capabilities on the underlying web server. As of the advisory date, no official patch is available, and users are advised to replace the theme.

Affected products

  • spicethemes SpicePress <= 2.3.2.5

Timeline

  • 2026-01-12: other: Vulnerability reported by researcher
  • 2026-02-11: advisory: Patchstack published advisory
  • 2026-04-08: disclosed: CVE published to NVD

References