CVE-2026-39640
mndpsingh287 Theme Editor
Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor theme-editor allows Code Injection.This issue affects Theme Editor: from n/a through <= 3.2.
- CVSS
- 9.6
- EPSS
- 0.14% 4.04% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.08