Junglewise Threat Intelligence

CVE-2026-39603: ThemeGoods Grand Photography CSRF in WordPress theme

CVE-2026-39603 · Severity: medium · CVSS 5.4 · Published 2026-04-08

Technologies: ThemeGoods Grand Photography. Vendors: ThemeGoods.

Executive brief

The Grand Photography theme for WordPress is vulnerable to a security flaw that could allow an attacker to trick an administrator into performing unintended actions. By getting a logged-in user to click a malicious link or visit a specific webpage, the attacker can trigger functions within the website's management interface without the user's consent. This could lead to unauthorized changes to site settings or content, potentially impacting the site's integrity and operations.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the ThemeGoods Grand Photography theme for WordPress through version 5.7.8. The issue stems from a lack of proper nonce validation or equivalent request verification mechanisms within the theme's administrative functions. An unauthenticated remote attacker can exploit this by crafting a malicious request and tricking a logged-in administrator or privileged user into executing it via social engineering (e.g., a malicious link). Successful exploitation allows the attacker to perform actions with the privileges of the victim user, such as modifying theme settings. As of the advisory date, no official patch has been released.

Affected products

  • ThemeGoods Grand Photography <= 5.7.8

Timeline

  • 2026-01-02: other: Vulnerability reported by Tran Nguyen Bao Khanh
  • 2026-02-01: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: CVE published

References

Related threats