Junglewise Threat Intelligence

CVE-2026-39637: SpabRice Mogi missing authorization in WordPress theme

CVE-2026-39637 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

The Mogi theme for WordPress contains a security flaw that fails to properly verify user permissions. This could allow an unauthorized person to execute arbitrary shortcodes, potentially leading to the exposure of sensitive information or unauthorized changes to website content. As of the latest report, there is no official patch available for this theme.

Technical details

A missing authorization vulnerability (CWE-862) exists in the SpabRice Mogi theme for WordPress through version 1.2.3. The flaw stems from incorrectly configured access control security levels, which fails to validate user permissions before executing certain functions. An unauthenticated remote attacker can exploit this to perform arbitrary shortcode execution. This can lead to information disclosure or further manipulation of the WordPress environment. No official patch has been released by the vendor.

Affected products

  • SpabRice Mogi <= 1.2.3

Timeline

  • 2026-01-14: other: Vulnerability reported by researcher João Pedro S Alcântara
  • 2026-02-13: advisory: Initial advisory published by Patchstack
  • 2026-04-08: disclosed: CVE published to NVD

References