Description
Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Photography grandphotography allows Cross Site Request Forgery.This issue affects Grand Photography: from n/a through <= 5.7.8.
Published: 2026-04-08
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized state changes via CSRF
Action: Apply Patch
AI Analysis

Impact

WordPress Grand Photography theme versions through 5.7.8 contain a Cross‑Site Request Forgery flaw that lets an attacker force an authenticated user to execute arbitrary actions within the site, such as creating posts, modifying settings or deleting content. The weakness lies in missing or unvalidated anti‑CSRF tokens, categorized under CWE‑352, and compromises the integrity of the application.

Affected Systems

Vendors affected are ThemeGoods, using the Grand Photography WordPress theme. All releases up to and including version 5.7.8 fall under the scope, whereas later releases are assumed fixed.

Risk and Exploitability

The issue presents a low‑to‑medium severity risk because the attacker must coerce a logged‑in user to visit a crafted URL while the session cookie is active. No public exploits are documented, EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. However, the potential for damage is significant if the site contains highly privileged users, and the attack can be automated with simple phishing or malicious links.

Generated by OpenCVE AI on April 8, 2026 at 09:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Grand Photography theme to the latest release after 5.7.8.
  • If upgrading is delayed, deactivate or remove the theme until a patch is applied.
  • Consider implementing additional CSRF protection such as nonce checks or a web‑application firewall.

Generated by OpenCVE AI on April 8, 2026 at 09:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Apr 2026 08:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Photography grandphotography allows Cross Site Request Forgery.This issue affects Grand Photography: from n/a through <= 5.7.8.
Title WordPress Grand Photography theme <= 5.7.8 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-08T08:30:22.019Z

Reserved: 2026-04-07T10:48:55.139Z

Link: CVE-2026-39603

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-08T09:16:29.467

Modified: 2026-04-08T21:26:35.910

Link: CVE-2026-39603

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-08T19:42:15Z

Weaknesses