Junglewise Threat Intelligence

CVE-2026-57785: ApusTheme ApusListing CSRF in WordPress theme

CVE-2026-57785 · Severity: high · CVSS 8.8 · Published 2026-07-23

Executive brief

ApusListing, a WordPress theme used for directory and listing websites, contains a security flaw that could allow an attacker to trick an administrator into performing unintended actions. By persuading a logged-in user to click a malicious link, an attacker could potentially gain unauthorized access or change site settings. This could lead to a full takeover of the website or the compromise of sensitive user data.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the ApusListing theme for WordPress due to insufficient validation of request origins. An unauthenticated remote attacker can exploit this by crafting a malicious request and tricking a high-privileged user (such as an administrator) into executing it via social engineering (e.g., a malicious link). Successful exploitation can lead to broken authentication, allowing the attacker to perform administrative actions or modify site configurations. The vulnerability is patched in version 1.2.64.

Affected products

  • ApusTheme ApusListing <= 1.2.63

Timeline

  • 2026-01-15: other: Vulnerability reported by researcher
  • 2026-02-14: disclosed: Initial disclosure by Patchstack
  • 2026-02-14: patched: Version 1.2.64 released to address the issue
  • 2026-07-23: advisory: NVD publication date

References