Junglewise Threat Intelligence

CVE-2026-39704: nfusionsolutions Precious Metals Automated Product Pricing , Pro broken access control

CVE-2026-39704 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

The Precious Metals Automated Product Pricing – Pro plugin for WordPress, which automates pricing for precious metal products, contains a security flaw that allows unauthorized access to certain functions. An attacker could exploit this to bypass intended security levels, potentially viewing sensitive pricing data or modifying configurations. This could lead to inaccurate product pricing on the website and financial or reputational damage.

Technical details

A missing authorization vulnerability (CWE-862) exists in the nfusionsolutions Precious Metals Automated Product Pricing – Pro plugin for WordPress through version 4.0.5. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing certain functions. An unauthenticated remote attacker can exploit this vulnerability to perform actions that should be restricted to higher-privileged users. According to the advisory, no official patch is currently available, and the vulnerability is classified as broken access control.

Affected products

  • nfusionsolutions Precious Metals Automated Product Pricing – Pro <= 4.0.5

Timeline

  • 2026-01-30: other: Vulnerability reported by researcher
  • 2026-03-01: disclosed: Vulnerability published by Patchstack
  • 2026-04-08: advisory: CVE published to NVD

References