Junglewise Threat Intelligence

CVE-2026-57769: ThemeGoods Grand Photography Reflected XSS

CVE-2026-57769 · Severity: high · CVSS 7.1 · Published 2026-07-23

Technologies: ThemeGoods Grand Photography. Vendors: ThemeGoods.

Executive brief

The Grand Photography theme for WordPress is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. This occurs when a victim clicks on a specially crafted link, potentially leading to unauthorized actions performed in the victim's browser, such as data theft or site redirection. As there is currently no official patch, website owners should exercise caution with suspicious links and consider using web application firewalls.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Grand Photography theme for WordPress (versions <= 5.7.8) due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted URL. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking or unauthorized administrative actions if the victim is logged in. As of the advisory date, no official patch has been released by the vendor.

Affected products

  • ThemeGoods Grand Photography <= 5.7.8

Timeline

  • 2026-01-02: other: Vulnerability reported by researcher
  • 2026-07-21: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: CVE published to NVD

References

Related threats