CVE-2026-39436: WordPress CformsII plugin <= 15.1.3 - Cross Site Request Forgery (CSRF) vulnerability
Published May 25, 2026
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery. This issue affects CformsII: from n/a through 15.1.3.
Affected Software
1 affected component
bgermann CformsII<=15.1.3
Remediation
Information
Update the WordPress CformsII Plugin to the latest available version (at least 15.1.4).
Event History
May 25, 2026
CVE Published
via MITRE·10:15 PM
Data Sourced
via MITRE·10:15 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-39436?
CVE-2026-39436 has a high severity rating of 7.1.
2
How do I fix CVE-2026-39436?
To fix CVE-2026-39436, update the WordPress CformsII plugin to at least version 15.1.4.
3
What type of vulnerability is CVE-2026-39436?
CVE-2026-39436 is a Cross Site Request Forgery (CSRF) vulnerability.
4
Which versions of the CformsII plugin are affected by CVE-2026-39436?
CVE-2026-39436 affects CformsII versions from n/a up to 15.1.3.
5
What potential risks does CVE-2026-39436 pose?
CVE-2026-39436 can allow attackers to execute unauthorized actions on behalf of a logged-in user.