Description
Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme pawfriends allows Cross Site Request Forgery.This issue affects PawFriends - Pet Shop and Veterinary WordPress Theme: from n/a through <= 1.3.
Published: 2026-01-22
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized state changes via CSRF
Action: Patch Theme
AI Analysis

Impact

The vulnerability is a classic Cross‑Site Request Forgery flaw that allows a malicious actor to force an authenticated user, such as a site administrator, to perform actions the user did not intend. The issue arises because the PawFriends theme does not validate the origin of certain requests, so a crafted link or script can change content, delete posts, or alter theme settings. Based on the description, it is inferred that any action that modifies site data or configuration could be performed without user consent, representing a moderate‑severity weakness classified as CWE‑352.

Affected Systems

The problem impacts the Mikado‑Themes PawFriends – Pet Shop and Veterinary WordPress Theme for all releases up to and including version 1.3. Users running those versions are susceptible; no other products are mentioned as affected.

Risk and Exploitability

With a CVSS score of 5.4 the vulnerability carries moderate severity, while the EPSS figure of less than 1 % suggests that exploitation is unlikely but not impossible. The likely attack vector is a browser‑based CSRF scenario that requires the victim to be logged into the WordPress admin area. Because the exploit does not require authentication to the theme itself, any user with administrative privileges can be coerced to trigger the malicious request. The consequence of unauthorized state changes can be significant for sites that host customer data or e‑commerce features, though the overall risk remains moderate due to the low exploitation probability.

Generated by OpenCVE AI on April 16, 2026 at 17:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest patched PawFriends theme that eliminates the CSRF flaw.
  • If an update cannot be applied immediately, temporarily deactivate the theme until the patch is available or switch to a secure alternative.
  • After updating, verify that CSRF protection is in place by confirming that all form submissions include a valid nonce or similar token.
  • Monitor administrative logs for suspicious activity and rotate any compromised credentials to reduce the impact of a potential breach.

Generated by OpenCVE AI on April 16, 2026 at 17:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 27 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 27 Jan 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Mikado-themes
Mikado-themes pawfriends - Pet Shop And Veterinary Wordpress Theme
Wordpress
Wordpress wordpress
Vendors & Products Mikado-themes
Mikado-themes pawfriends - Pet Shop And Veterinary Wordpress Theme
Wordpress
Wordpress wordpress

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme pawfriends allows Cross Site Request Forgery.This issue affects PawFriends - Pet Shop and Veterinary WordPress Theme: from n/a through <= 1.3.
Title WordPress PawFriends - Pet Shop and Veterinary WordPress Theme theme <= 1.3 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References

Subscriptions

Mikado-themes Pawfriends - Pet Shop And Veterinary Wordpress Theme
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:53:22.017Z

Reserved: 2026-01-07T12:21:36.722Z

Link: CVE-2026-22382

cve-icon Vulnrichment

Updated: 2026-01-27T20:11:18.673Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:16:32.233

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-22382

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T18:00:11Z

Weaknesses