
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-39659 was initially reported as a Missing Authorization vulnerability (CWE-862) in the Ultimate Member WordPress plugin, affecting versions through 2.11.3, that could allow exploitation of incorrectly configured access control security levels. It was published on April 8, 2026, by Patchstack, and carried a CVSS v3.1 base score of 5.3 (Medium) at the time of initial disclosure. This CVE has since been officially rejected and withdrawn by its CVE Numbering Authority (Patchstack) on April 21, 2026, and is no longer considered a valid vulnerability entry (GitHub Advisory).
As originally described before rejection, the vulnerability was classified under CWE-862 (Missing Authorization), where the Ultimate Member plugin allegedly failed to perform proper authorization checks when actors attempted to access protected resources or perform restricted actions. The issue was said to affect incorrectly configured access control security levels in plugin versions up to and including 2.11.3. Because the CVE was subsequently rejected by Patchstack, the underlying technical details may reflect a duplicate, incorrectly scoped, or otherwise invalid report rather than a confirmed distinct vulnerability (GitHub Advisory).
Given the CVE's rejected status, no confirmed impact can be attributed to this specific identifier. The original description suggested potential unauthorized access to protected functionality, possible privilege escalation, and limited confidentiality impact (low), with no integrity or availability impact assessed. Any real-world risk associated with access control weaknesses in Ultimate Member should be evaluated against other valid, non-rejected advisories for the plugin (GitHub Advisory).
There is no evidence of a public proof-of-concept exploit or in-the-wild exploitation associated with CVE-2026-39659. The EPSS score is approximately 0.017–0.037%, indicating a very low probability of exploitation. The CVE has been rejected by its numbering authority and is not listed in the CISA Known Exploited Vulnerabilities catalog (GitHub Advisory).
Because CVE-2026-39659 has been officially rejected and withdrawn by Patchstack, no specific remediation is required for this CVE identifier. Organizations using the Ultimate Member WordPress plugin should nonetheless maintain up-to-date plugin versions and review access control configurations as a general security practice. Any concerns about access control weaknesses in Ultimate Member should be cross-referenced against valid, active advisories from Patchstack or the WordPress plugin repository (GitHub Advisory).
The CVE received minimal community attention given its short lifespan before rejection. It was briefly indexed by vulnerability aggregators such as VulDB and cve.report, and appeared in automated CVE notification feeds, but no notable researcher commentary or media coverage was generated. The rejection by Patchstack on April 21, 2026, effectively ended any substantive discussion (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."