Executive brief
The WordPress Dating Theme, used to build dating and community websites, contains a security flaw that could allow an attacker to take over user accounts. By tricking a site administrator or other high-privileged user into clicking a malicious link, an attacker can force the website to perform unauthorized actions. This could lead to a full compromise of the website's data and administrative controls.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Dating Theme (DA10) by PremiumPress Limited through version 11.2.0. The flaw is caused by a lack of proper nonce validation or anti-CSRF tokens on sensitive administrative or account-related actions. An unauthenticated remote attacker can exploit this by inducing a logged-in user (such as an administrator) to visit a specially crafted webpage or click a malicious link. Successful exploitation can lead to unauthorized account takeover or other high-impact administrative actions. As of the advisory date, no official patch has been released.
Affected products
- PremiumPress Limited. WordPress Dating Theme (DA10) <= 11.2.0
Timeline
- 2025-11-23: other: Reported by researcher 0xd4rk5id3
- 2025-12-23: disclosed: Initial disclosure by Patchstack
- 2026-06-17: advisory: CVE published and NVD record created