Junglewise Threat Intelligence

CVE-2026-22342: PremiumPress WordPress Dating Theme CSRF to Account Takeover

CVE-2026-22342 · Severity: high · CVSS 8.8 · Published 2026-06-17

Executive brief

The WordPress Dating Theme, used to build dating and community websites, contains a security flaw that could allow an attacker to take over user accounts. By tricking a site administrator or other high-privileged user into clicking a malicious link, an attacker can force the website to perform unauthorized actions. This could lead to a full compromise of the website's data and administrative controls.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Dating Theme (DA10) by PremiumPress Limited through version 11.2.0. The flaw is caused by a lack of proper nonce validation or anti-CSRF tokens on sensitive administrative or account-related actions. An unauthenticated remote attacker can exploit this by inducing a logged-in user (such as an administrator) to visit a specially crafted webpage or click a malicious link. Successful exploitation can lead to unauthorized account takeover or other high-impact administrative actions. As of the advisory date, no official patch has been released.

Affected products

  • PremiumPress Limited. WordPress Dating Theme (DA10) <= 11.2.0

Timeline

  • 2025-11-23: other: Reported by researcher 0xd4rk5id3
  • 2025-12-23: disclosed: Initial disclosure by Patchstack
  • 2026-06-17: advisory: CVE published and NVD record created

References

Related threats