Junglewise Threat Intelligence

CVE-2026-57655: Jay Versluis Child Theme Wizard CSRF

CVE-2026-57655 · Severity: high · CVSS 8.2 · Published 2026-06-26

Executive brief

Child Theme Wizard is a WordPress plugin used to easily create child themes for website customization. A security flaw allows an attacker to trick a site administrator into performing unintended actions, such as modifying theme settings or creating unauthorized files, by clicking a malicious link. This could lead to unauthorized changes to the website's appearance or configuration.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Child Theme Wizard plugin for WordPress in versions up to and including 1.4. The vulnerability stems from a lack of nonce validation or insufficient check on sensitive actions within the plugin's administrative interface. An unauthenticated remote attacker can exploit this by tricking a logged-in administrator into visiting a specially crafted webpage or clicking a malicious link. Successful exploitation allows the attacker to perform actions with the privileges of the administrator, such as generating new child themes or modifying existing ones. The issue is resolved in version 1.5.

Affected products

  • Jay Versluis Child Theme Wizard <= 1.4

Timeline

  • 2026-06-12: disclosed: Reported by Ananda Dhakal via Patchstack
  • 2026-06-26: advisory: Public advisory published by Patchstack and NVD
  • 2026-06-26: patched: Patch released in version 1.5

References