CVE-2026-39589CRITICAL NVDCVSS Score 9.9Severity CRITICALPublished Jun 17, 2026Vendor unknownDescriptionSubscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions.Referenceshttps://patchstack.com/database/wordpress/theme/webenvo/vulnerability/wordpress-webenvo-theme-0-0-6-arbitrary-file-upload-vulnerability?_s_id=cve