Junglewise Threat Intelligence

CVE-2026-39635: ThemeGoods Grand Magazine CSRF in WordPress theme

CVE-2026-39635 · Severity: medium · CVSS 5.4 · Published 2026-04-08

Vendors: ThemeGoods.

Executive brief

The Grand Magazine theme for WordPress is vulnerable to a security flaw that could allow an attacker to trick an authorized user into performing unintended actions. By convincing a site administrator or editor to click a malicious link, an attacker could potentially change site settings or modify content without permission. This could lead to unauthorized changes to the website's appearance or configuration.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the ThemeGoods Grand Magazine theme for WordPress (versions up to and including 3.5.5). The vulnerability stems from a lack of proper nonce validation on sensitive administrative or configuration actions within the theme. An unauthenticated attacker can exploit this by crafting a malicious webpage or link and tricking a logged-in user with sufficient privileges (such as an administrator) into interacting with it. Successful exploitation allows the attacker to perform actions on behalf of the victim, potentially leading to unauthorized modification of site settings or content. As of the advisory date, no official patch has been released.

Affected products

  • ThemeGoods Grand Magazine <= 3.5.5

Timeline

  • 2026-01-14: other: Vulnerability reported by researcher
  • 2026-02-13: advisory: Initial disclosure by Patchstack
  • 2026-04-08: disclosed: CVE published to NVD

References