CVE-2026-39659
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-39659 was initially reported as a Missing Authorization vulnerability (CWE-862) in the Ultimate Member WordPress plugin, affecting versions through 2.11.3, that could allow exploitation of incorrectly configured access control security levels. It was published on April 8, 2026, by Patchstack, and carried a CVSS v3.1 base score of 5.3 (Medium) at the time of initial disclosure. This CVE has since been officially rejected and withdrawn by its CVE Numbering Authority (Patchstack) on April 21, 2026, and is no longer considered a valid vulnerability entry (GitHub Advisory).

Technical details

As originally described before rejection, the vulnerability was classified under CWE-862 (Missing Authorization), where the Ultimate Member plugin allegedly failed to perform proper authorization checks when actors attempted to access protected resources or perform restricted actions. The issue was said to affect incorrectly configured access control security levels in plugin versions up to and including 2.11.3. Because the CVE was subsequently rejected by Patchstack, the underlying technical details may reflect a duplicate, incorrectly scoped, or otherwise invalid report rather than a confirmed distinct vulnerability (GitHub Advisory).

Impact

Given the CVE's rejected status, no confirmed impact can be attributed to this specific identifier. The original description suggested potential unauthorized access to protected functionality, possible privilege escalation, and limited confidentiality impact (low), with no integrity or availability impact assessed. Any real-world risk associated with access control weaknesses in Ultimate Member should be evaluated against other valid, non-rejected advisories for the plugin (GitHub Advisory).

Exploitability

There is no evidence of a public proof-of-concept exploit or in-the-wild exploitation associated with CVE-2026-39659. The EPSS score is approximately 0.017–0.037%, indicating a very low probability of exploitation. The CVE has been rejected by its numbering authority and is not listed in the CISA Known Exploited Vulnerabilities catalog (GitHub Advisory).

Mitigation and workarounds

Because CVE-2026-39659 has been officially rejected and withdrawn by Patchstack, no specific remediation is required for this CVE identifier. Organizations using the Ultimate Member WordPress plugin should nonetheless maintain up-to-date plugin versions and review access control configurations as a general security practice. Any concerns about access control weaknesses in Ultimate Member should be cross-referenced against valid, active advisories from Patchstack or the WordPress plugin repository (GitHub Advisory).

Community reactions

The CVE received minimal community attention given its short lifespan before rejection. It was briefly indexed by vulnerability aggregators such as VulDB and cve.report, and appeared in automated CVE notification feeds, but no notable researcher commentary or media coverage was generated. The rejection by Patchstack on April 21, 2026, effectively ended any substantive discussion (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78570CRITICAL9.8
  • totaldonations
NoNoAug 25, 2026
CVE-2026-78568CRITICAL9.8
  • totaldonations
NoNoAug 25, 2026
CVE-2026-78572HIGH8.1
  • kalles-addons
NoNoAug 25, 2026
CVE-2026-78576HIGH7.5
  • readabler
NoYesAug 25, 2026
CVE-2026-76128MEDIUM6.4
  • ecommerce-product-catalog
NoYesAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management