Junglewise Threat Intelligence

CVE-2026-39714: G5Theme G5Plus April missing authorization in WordPress theme

CVE-2026-39714 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

G5Plus April is a professional WordPress theme used for building websites. A security flaw in the theme's access control settings could allow unauthorized individuals to access information or perform actions that should be restricted to administrators. This could lead to unauthorized data exposure or minor disruptions to the website's operations.

Technical details

The G5Plus April theme for WordPress (versions up to and including 6.8) contains a broken access control vulnerability (CWE-862). The flaw stems from missing authorization checks or incorrectly configured security levels within the theme's functions. An unauthenticated remote attacker can exploit this over the network to bypass intended access restrictions. While the specific impact is categorized as partial, it typically allows for unauthorized information disclosure or the execution of restricted functions. As of the advisory date, no official patch has been released.

Affected products

  • G5Theme G5Plus April <= 6.8

Timeline

  • 2026-01-31: other: Vulnerability reported by researcher Phat RiO
  • 2026-03-02: disclosed: Vulnerability published by Patchstack
  • 2026-04-08: advisory: CVE-2026-39714 published to NVD

References