Impact
The Wallstreet WordPress theme contains a cross‑site request forgery flaw that lets an attacker cause a logged‑in user to submit privileged requests without the user's knowledge. The result is that the attacker can invoke any state‑changing action provided by the theme, potentially modifying content, settings, or user data. This weakness is classified as CWE‑352.
Affected Systems
Any installation of the Webriti Wallstreet theme up to and including version 2.8.6 is affected. Earlier releases share the same vulnerability.
Risk and Exploitability
The CVSS score of 8.8 denotes high severity. No EPSS score is available, so current exploitation probability cannot be quantified, and the vulnerability is not yet listed in CISA KEV. The flaw is exploitable by having a victim visit a crafted URL or submit a malicious form while authenticated. The likely attack vector therefore involves social engineering or compromised content that makes the victim’s browser submit the forged request. Consequently, sites using the vulnerable theme face a substantial risk of unauthorized actions if no mitigation is applied.
OpenCVE Enrichment