Impact
A cross‑site request forgery vulnerability exists in the Grand Photography theme for WordPress, allowing an attacker to craft requests that are executed with the victim's authenticated session. This weakness aligns with CWE‑352 and can enable unauthorized actions within the site.
Affected Systems
The flaw applies to WordPress sites that employ the Grand Photography theme version 5.7.8 or earlier from ThemeGoods. Any installation that has not upgraded beyond this point remains vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while the reported exploitation probability is below 1%, implying low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attacks would require tricking an authenticated administrator into visiting a malicious webpage that triggers the forged request. Overall risk is moderate, and administrators should address it promptly.
OpenCVE Enrichment