CVE-2026-39621
spicethemes SpicePress
Cross-Site Request Forgery (CSRF) vulnerability in spicethemes SpicePress spicepress allows Upload a Web Shell to a Web Server.This issue affects SpicePress: from n/a through <= 2.3.2.5.
- CVSS
- 8.8
- EPSS
- 0.14% 4.04% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.08