Junglewise Threat Intelligence

CVE-2026-39633: ThemeGoods Grand Car Rental CSRF in WordPress theme

CVE-2026-39633 · Severity: medium · CVSS 6.5 · Published 2026-04-08

Vendors: ThemeGoods.

Executive brief

ThemeGoods Grand Car Rental, a WordPress theme used for car rental business websites, is vulnerable to a security flaw that could allow an attacker to trick an administrator into performing unintended actions. By persuading a logged-in user to click a malicious link or visit a specific webpage, an attacker could potentially modify site settings or data without the user's knowledge. This could lead to unauthorized changes to the website's configuration or rental information.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the ThemeGoods Grand Car Rental theme for WordPress through version 3.6.9. The flaw is rooted in a lack of proper nonce validation or equivalent CSRF protections within the theme's administrative functions. An unauthenticated remote attacker can exploit this by crafting a malicious request and tricking a logged-in administrator or privileged user into executing it via social engineering (e.g., a malicious link). Successful exploitation allows the attacker to perform actions with the privileges of the victim user, such as modifying theme settings or site content. As of the advisory date, no official patch has been released.

Affected products

  • ThemeGoods Grand Car Rental <= 3.6.9

Timeline

  • 2026-01-14: other: Vulnerability reported by researcher
  • 2026-02-13: advisory: Patchstack published advisory
  • 2026-04-08: disclosed: CVE published to NVD

References

Related threats