Impact
A security flaw allows a malicious site to trick a logged‑in user into sending a forged request to the WordPress Grand Blog theme, enabling unintended state changes. The weakness is classified as CWE‑352. Based on the description, it is inferred that the theme does not enforce CSRF tokens before processing requests, allowing an attacker to manipulate site actions without the user’s knowledge.
Affected Systems
WordPress installations using the ThemeGoods Grand Blog theme version 3.1 or earlier are affected. Every instance of the theme up to and including 3.1 is vulnerable, irrespective of the underlying WordPress core version.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of current exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is a crafted HTTP request or form submission that exploits the missing CSRF protection while the user is authenticated, as inferred from the description.
OpenCVE Enrichment