Description
Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bluestreet allows Cross Site Request Forgery.This issue affects Bluestreet: from n/a through <= 1.7.3.
Published: 2026-04-08
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary Plugin Installation via CSRF
Action: Patch Immediately
AI Analysis

Impact

This flaw is a cross‑site request forgery that permits an attacker to trigger the installation of any WordPress plugin on a site using the affected theme. The installation process can include malicious code, giving the attacker the same level of control that a legitimate plugin could provide. The weakness matches CWE‑352, the classic CSRF defect that allows unauthorized actions under a victim’s authenticated session.

Affected Systems

WordPress sites that have installed the Bluestreet theme by Priyanshu Mittal with a version of 1.7.3 or earlier are affected. No other vendors or products are listed in the CNA data, and no additional version ranges are specified beyond the upper bound of 1.7.3.

Risk and Exploitability

The necessary condition for exploitation is an authenticated user session with permission to install plugins, and the ability to click a specially crafted link that submits an installation request. Based on the description, it is inferred that the attacker must entice a user to visit the forged URL through social engineering or embedded links. Because the vulnerability is a standard CSRF pattern and the CAPABILITY to install plugins can be granted to non‑administrator accounts, the risk is high on sites with permissive install options. The CVSS score is not reported, the EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. Nevertheless, the potential for arbitrary code execution makes the threat significant.

Generated by OpenCVE AI on April 8, 2026 at 11:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Bluestreet theme to a version newer than 1.7.3.
  • If upgrading is not immediately possible, deactivate or remove the Bluestreet theme to eliminate the attack surface.
  • After applying a fix, review and delete any plugins that may have been installed through CSRF exploitation.
  • Restrict the ability to install plugins to administrator accounts only and monitor install logs for suspicious activity.

Generated by OpenCVE AI on April 8, 2026 at 11:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Apr 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Priyanshumittal
Priyanshumittal bluestreet
Wordpress
Wordpress wordpress
Vendors & Products Priyanshumittal
Priyanshumittal bluestreet
Wordpress
Wordpress wordpress

Wed, 08 Apr 2026 08:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bluestreet allows Cross Site Request Forgery.This issue affects Bluestreet: from n/a through <= 1.7.3.
Title WordPress Bluestreet theme <= 1.7.3 - Cross Site Request Forgery (CSRF) to Arbitrary Plugin Installation vulnerability
Weaknesses CWE-352
References

Subscriptions

Priyanshumittal Bluestreet
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-08T08:30:25.380Z

Reserved: 2026-04-07T10:57:27.974Z

Link: CVE-2026-39617

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-08T09:16:31.600

Modified: 2026-04-08T21:26:35.910

Link: CVE-2026-39617

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-08T19:41:59Z

Weaknesses