Junglewise Threat Intelligence

CVE-2026-39668: g5theme Book Previewer for Woocommerce missing authorization

CVE-2026-39668 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

The Book Previewer for Woocommerce plugin, which allows customers to view book samples on e-commerce sites, contains a security flaw in its access control settings. This vulnerability could allow an unauthorized person to access information or perform actions that should be restricted to administrators or specific users. While the impact is considered moderate, it could lead to the exposure of internal data or unauthorized changes to how book previews are managed.

Technical details

A missing authorization vulnerability (CWE-862) exists in the g5theme Book Previewer for Woocommerce plugin through version 1.0.6. The issue stems from incorrectly configured access control security levels within the plugin's functional logic. An unauthenticated remote attacker can exploit this flaw to bypass intended restrictions and execute actions or access data that should require higher privilege levels. As of the advisory date, no official patch has been released, and users are advised to monitor for updates from the developer.

Affected products

  • g5theme Book Previewer for Woocommerce <= 1.0.6

Timeline

  • 2026-01-19: other: Vulnerability reported by researcher Steven Julian
  • 2026-02-18: advisory: Initial advisory published by Patchstack
  • 2026-04-08: disclosed: CVE published to NVD

References