Executive brief
A security vulnerability exists in the Grand Blog theme for WordPress, which is used to design and manage blogging websites. This flaw allows an attacker to trick a site administrator into performing unintended actions, such as changing site settings or deleting content, by getting them to click a malicious link. If successfully exploited, this could lead to unauthorized modifications of the website's configuration or data.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the ThemeGoods Grand Blog theme for WordPress through version 3.1. The vulnerability stems from a lack of proper nonce validation or equivalent CSRF protections in certain administrative functions. An unauthenticated remote attacker can exploit this by inducing a logged-in administrator or high-privileged user to visit a specially crafted webpage or click a malicious link. Successful exploitation allows the attacker to execute state-changing actions on the WordPress site with the permissions of the victim user. As of the advisory date, no official patch has been released.
Affected products
- ThemeGoods Grand Blog <= 3.1
Timeline
- 2026-01-14: other: Vulnerability reported by researcher
- 2026-02-13: advisory: Patchstack published advisory
- 2026-04-08: disclosed: CVE published to NVD