Junglewise Threat Intelligence

CVE-2026-39682: Arjan Pronk linkPizza-Manager missing authorization

CVE-2026-39682 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

The linkPizza-Manager plugin for WordPress, which helps site owners manage affiliate links and monetization, contains a security flaw in its access control settings. An unauthorized person could potentially perform actions or modify settings that should be restricted to administrators. This could lead to unauthorized changes to how affiliate links are managed on the website.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Arjan Pronk linkPizza-Manager plugin for WordPress through version 5.5.5. The vulnerability stems from a failure to implement proper permission checks or nonce validation on certain functions, allowing unauthenticated remote attackers to bypass intended access control security levels. Depending on the specific endpoint affected, an attacker could potentially modify plugin configurations or execute restricted actions. The issue is resolved in version 5.6.0.

Affected products

  • Arjan Pronk linkPizza-Manager <= 5.5.5

Timeline

  • 2026-01-22: other: Vulnerability reported by researcher Nabil Irawan
  • 2026-02-21: patched: Version 5.6.0 released to address the issue
  • 2026-04-08: disclosed: CVE published

References