Critical 9.6 Unfixed
2026-04-08≤ 2.5.2
CVE-2026-39619
Minimum safe version
2.3.8
Update to 2.3.8 or later to address 2 fixable vulnerabilities
CVE-2026-39619
CVE-2024-43262
Multiple Themes - Reflected Cross-Site Scripting via Customizer Notify
Multiple Themes (Various Versions) - Reflected Cross-Site Scripting