PatchDay Alert

CVE

CVE-2026-39440

0field notes · 1digest CVSS 9.9


Daily digests

An attacker can inject and execute arbitrary code remotely through FunnelFormsPro, the WordPress plugin. This is a code injection bug with a CVSS of 9.9. All versions through 3.8.1 are vulnerable.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.