Junglewise Threat Intelligence

CVE-2026-39640: mndpsingh287 Theme Editor CSRF and Code Injection

CVE-2026-39640 · Severity: critical · CVSS 9.6 · Published 2026-04-08

Executive brief

The Theme Editor plugin for WordPress, which allows administrators to edit site files directly, contains a security flaw that could allow an attacker to inject malicious code. By tricking a logged-in administrator into clicking a malicious link or visiting a compromised website, an attacker can force the plugin to execute unauthorized commands. This could lead to a full takeover of the website, theft of customer data, or the installation of ransomware.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the mndpsingh287 Theme Editor plugin (versions up to and including 3.2) due to insufficient validation of request origins. An unauthenticated remote attacker can exploit this by crafting a malicious request and tricking a highly privileged user (such as an administrator) into executing it while authenticated. Successful exploitation allows for arbitrary code injection, which can lead to Remote Code Execution (RCE) and full site compromise. As of the advisory date, no official patch has been released.

Affected products

  • mndpsingh287 Theme Editor <= 3.2

Timeline

  • 2026-01-15: other: Vulnerability reported by researcher hhhai
  • 2026-02-14: advisory: Initial advisory published by Patchstack
  • 2026-04-08: disclosed: CVE published to NVD

References

Related threats