Junglewise Threat Intelligence

CVE-2026-39686: bannersky BSK PDF Manager sensitive information disclosure

CVE-2026-39686 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

BSK PDF Manager is a WordPress plugin used to manage and display PDF documents on websites. A security vulnerability in this plugin allows unauthorized individuals to access sensitive system information that should be protected. This could potentially expose internal data or configuration details, which attackers might use to plan further actions against the website.

Technical details

An Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) vulnerability exists in the BSK PDF Manager plugin for WordPress. The flaw allows an unauthenticated remote attacker to retrieve embedded sensitive data from the system. The vulnerability stems from improper access controls or insufficient sanitization within the plugin's management components. As of the latest advisory, no official patch has been released for versions up to and including 3.7.2. The attack can be carried out over the network without any user interaction.

Affected products

  • bannersky BSK PDF Manager <= 3.7.2

Timeline

  • 2026-01-23: other: Vulnerability reported by researcher Doan Dinh Van
  • 2026-02-22: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: CVE published to NVD

References