Junglewise Threat Intelligence

CVE-2026-66652: ThemeGoods Grand Tour cross-site request forgery

CVE-2026-66652 · Severity: medium · CVSS 5.4 · Published 2026-09-02

Vendors: ThemeGoods.

Executive brief

Grand Tour is a WordPress theme used to build and manage website content and appearance. A cross-site request forgery (CSRF) vulnerability allows attackers to trick logged-in administrators into performing unintended actions—such as changing settings, deleting content, or modifying site configuration—without their knowledge or consent. This could compromise site integrity and administrator accounts.

Technical details

The Grand Tour WordPress theme versions 5.5.1 and earlier contain a cross-site request forgery vulnerability that allows unauthenticated attackers to craft malicious web pages or links that, when clicked by a logged-in administrator, trigger unwanted administrative actions. The vulnerability exploits the absence of proper CSRF token validation on sensitive operations. Successful exploitation requires user interaction (a logged-in user must visit a malicious page or click a crafted link). The impact includes unauthorized modification of site settings and potential administrative account compromise. No official patch is currently available; administrators should update to a patched version or implement additional security controls.

Affected products

  • ThemeGoods Grand Tour through 5.5.1

Timeline

  • 2026-01-02: disclosed: Reported to Patchstack
  • 2026-09-02: advisory: Published by Patchstack and NVD

References