Impact
The vulnerability is a CSRF flaw present in the ThemeGoods Grand Magazine theme for WordPress up to version 3.5.5. It permits an attacker to convince an authenticated user to submit a request that changes site state. Based on the description, this could include modifying the theme’s settings or performing other state‑changing actions that require the user’s credentials.
Affected Systems
WordPress sites utilizing the ThemeGoods Grand Magazine theme from the earliest releases through 3.5.5 are affected. The issue is limited to this theme and does not involve WordPress core components.
Risk and Exploitability
The CVSS base score of 5.4 indicates medium severity, while the EPSS score of less than 1 % suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The typical CSRF attack involves an attacker luring a logged‑in user to visit a crafted URL; this inference is drawn from the nature of CSRF vulnerabilities and the description, as the exact attack vector is not specified.
OpenCVE Enrichment