Junglewise Threat Intelligence

CVE-2026-39632: ThemeGoods Grand Blog CSRF in WordPress theme

CVE-2026-39632 · Severity: medium · CVSS 6.5 · Published 2026-04-08

Vendors: ThemeGoods.

Executive brief

A security vulnerability exists in the Grand Blog theme for WordPress, which is used to design and manage blogging websites. This flaw allows an attacker to trick a site administrator into performing unintended actions, such as changing site settings or deleting content, by getting them to click a malicious link. If successfully exploited, this could lead to unauthorized modifications of the website's configuration or data.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the ThemeGoods Grand Blog theme for WordPress through version 3.1. The vulnerability stems from a lack of proper nonce validation or equivalent CSRF protections in certain administrative functions. An unauthenticated remote attacker can exploit this by inducing a logged-in administrator or high-privileged user to visit a specially crafted webpage or click a malicious link. Successful exploitation allows the attacker to execute state-changing actions on the WordPress site with the permissions of the victim user. As of the advisory date, no official patch has been released.

Affected products

  • ThemeGoods Grand Blog <= 3.1

Timeline

  • 2026-01-14: other: Vulnerability reported by researcher
  • 2026-02-13: advisory: Patchstack published advisory
  • 2026-04-08: disclosed: CVE published to NVD

References