Executive brief
YOOtheme Zoo is a popular Joomla extension that provides content management and display capabilities for Joomla websites. The extension fails to implement CSRF (Cross-Site Request Forgery) protections on front-end state-changing operations, allowing attackers to trick users into performing unintended actions such as modifying content or settings without their knowledge.
Technical details
This vulnerability is a Cross-Site Request Forgery (CSRF) issue in YOOtheme Zoo versions before 4.1.66, where front-end state-changing operations lack proper CSRF token validation. An attacker can craft a malicious webpage or email that, when visited by an authenticated Zoo user, silently executes state-changing actions without the user's explicit consent. The attack vector is network-based and requires no special privileges, though it does require the user to be authenticated and visit an attacker-controlled page while logged in. Affected versions prior to 4.1.66 are vulnerable; users should upgrade to 4.1.66 or later to remediate.
Affected products
- YOOtheme Zoo < 4.1.66
Timeline
- 2026-08-21: disclosed