Junglewise Threat Intelligence

CVE-2026-57690: Fuelthemes Werkstatt CSRF in WordPress theme

CVE-2026-57690 · Severity: medium · CVSS 4.3 · Published 2026-07-02

Technologies: Fuelthemes Werkstatt. Vendors: Fuelthemes.

Executive brief

Werkstatt, a premium WordPress theme, contains a security flaw that could allow an attacker to trick a site administrator into performing unintended actions. By persuading a logged-in user to click a malicious link or visit a specially crafted webpage, an attacker could modify site settings or data without the user's knowledge. This could lead to unauthorized changes to the website's configuration or content.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Fuelthemes Werkstatt theme for WordPress through version 4.7.2. The issue stems from a lack of proper nonce validation or equivalent CSRF protections on sensitive state-changing functions within the theme. An unauthenticated remote attacker can exploit this by crafting a malicious request and tricking a logged-in administrator into executing it via social engineering (e.g., a malicious link or hidden form). Successful exploitation allows the attacker to perform unauthorized actions with the privileges of the victim user, potentially altering site settings. As of the advisory date, no official patch has been released.

Affected products

  • Fuelthemes Werkstatt <= 4.7.2

Timeline

  • 2024-09-17: other: Vulnerability reported by researcher
  • 2026-06-29: advisory: Initial advisory published by Patchstack
  • 2026-07-02: disclosed: CVE published in NVD

References