Junglewise Threat Intelligence

CVE-2026-39617: priyanshumittal Bluestreet CSRF to arbitrary plugin installation

CVE-2026-39617 · Severity: critical · CVSS 9.6 · Published 2026-04-08

Executive brief

Bluestreet is a theme used for WordPress websites. A security flaw allows an attacker to trick a site administrator into performing unintended actions, such as installing unauthorized plugins. This could lead to a full takeover of the website, potentially resulting in data theft or the site being used to host malicious content.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Bluestreet theme for WordPress due to insufficient validation of request origins on administrative functions. An unauthenticated remote attacker can exploit this by crafting a malicious web page or link and tricking a site administrator into interacting with it while authenticated. Successful exploitation allows the attacker to execute arbitrary actions with the administrator's privileges, specifically including the installation of arbitrary plugins, which can lead to Remote Code Execution (RCE) and full site compromise. As of the advisory date, no official patch is available, and users are advised to replace the theme.

Affected products

  • priyanshumittal Bluestreet <= 1.7.3 (NVD); <= 1.7.4 (Patchstack)

Timeline

  • 2026-01-12: other: Vulnerability reported by researcher
  • 2026-02-11: advisory: Patchstack advisory published
  • 2026-04-08: disclosed: CVE published to NVD

References