Junglewise Threat Intelligence

CVE-2026-39634: ThemeGoods Grand Portfolio CSRF in WordPress theme

CVE-2026-39634 · Severity: medium · CVSS 5.4 · Published 2026-04-08

Vendors: ThemeGoods.

Executive brief

ThemeGoods Grand Portfolio, a WordPress theme used for creating professional photography and creative portfolios, is vulnerable to a security flaw that could allow an attacker to trick an administrator into performing unintended actions. By convincing a logged-in user to click a malicious link or visit a specific webpage, an attacker could potentially modify site settings or content without authorization. This could lead to unauthorized changes to the website's appearance or configuration, impacting the site's integrity.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the ThemeGoods Grand Portfolio theme for WordPress through version 3.3. The vulnerability is caused by a lack of proper nonce validation or equivalent request verification mechanisms within the theme's administrative functions. An unauthenticated remote attacker can exploit this by crafting a malicious request and tricking a high-privileged user (such as an administrator) into executing it via social engineering (e.g., a malicious link). Successful exploitation allows the attacker to perform unauthorized actions with the privileges of the victim user, such as modifying theme settings. As of the advisory date, no official patch has been released.

Affected products

  • ThemeGoods Grand Portfolio <= 3.3

Timeline

  • 2026-01-14: other: Vulnerability reported by Tran Nguyen Bao Khanh
  • 2026-02-13: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: CVE published to NVD

References