Junglewise Threat Intelligence

CVE-2026-39648: themebeez Cream Blog missing authorization in WordPress theme

CVE-2026-39648 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

The Cream Blog theme for WordPress contains a security flaw where it fails to properly check user permissions for certain actions. This could allow an unauthorized person to perform administrative or restricted tasks on the website without permission. Because the theme has not been updated in over a year, users are advised to replace it with a supported alternative to maintain site security.

Technical details

A missing authorization vulnerability (CWE-862) exists in the themebeez Cream Blog theme for WordPress through version 2.1.7. The flaw stems from a failure to implement proper access control checks or nonce validation on sensitive functions. An unauthenticated remote attacker can exploit this to execute actions that should be restricted to higher-privileged users. As the software has not been updated recently and no official patch is available, security researchers recommend removing and replacing the theme.

Affected products

  • themebeez Cream Blog <= 2.1.7

Timeline

  • 2026-01-16: other: Vulnerability reported by researcher Legion Hunter
  • 2026-02-15: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: CVE published

References