Junglewise Threat Intelligence

CVE-2026-39641: Skywarrior Blackfyre CSRF in WordPress theme

CVE-2026-39641 · Severity: medium · CVSS 6.5 · Published 2026-04-08

Executive brief

Blackfyre is a WordPress theme used to create gaming communities and websites. A security flaw allows an attacker to trick an authorized user (like an administrator) into performing unintended actions on the site without their knowledge. This could lead to unauthorized changes to site settings or content if a logged-in user clicks on a malicious link.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Skywarrior Blackfyre theme for WordPress through version 2.5.4. The vulnerability stems from a lack of proper nonce validation or equivalent protection on sensitive administrative actions. An unauthenticated remote attacker can exploit this by tricking a logged-in user with high privileges into visiting a specially crafted webpage or clicking a malicious link. Successful exploitation allows the attacker to execute actions on behalf of the victim, potentially leading to unauthorized configuration changes or data modification. As of the advisory date, no official patch has been released.

Affected products

  • Skywarrior Blackfyre <= 2.5.4

Timeline

  • 2026-01-15: other: Vulnerability reported by researcher
  • 2026-02-14: advisory: Initial advisory published by Patchstack
  • 2026-04-08: disclosed: CVE published to NVD

References