Description
Cross-Site Request Forgery (CSRF) vulnerability in Webriti Wallstreet wallstreet allows Cross Site Request Forgery.This issue affects Wallstreet: from n/a through 2.8.6.
Published: 2026-10-02
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Unauthorized actions via CSRF
Action: Update Theme
AI Analysis

Impact

The Wallstreet WordPress theme contains a cross‑site request forgery flaw that lets an attacker cause a logged‑in user to submit privileged requests without the user's knowledge. The result is that the attacker can invoke any state‑changing action provided by the theme, potentially modifying content, settings, or user data. This weakness is classified as CWE‑352.

Affected Systems

Any installation of the Webriti Wallstreet theme up to and including version 2.8.6 is affected. Earlier releases share the same vulnerability.

Risk and Exploitability

The CVSS score of 8.8 denotes high severity. No EPSS score is available, so current exploitation probability cannot be quantified, and the vulnerability is not yet listed in CISA KEV. The flaw is exploitable by having a victim visit a crafted URL or submit a malicious form while authenticated. The likely attack vector therefore involves social engineering or compromised content that makes the victim’s browser submit the forged request. Consequently, sites using the vulnerable theme face a substantial risk of unauthorized actions if no mitigation is applied.

Generated by OpenCVE AI on October 2, 2026 at 20:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Wallstreet theme to version 2.8.7 or later to remove the CSRF flaw.
  • If a theme update cannot be performed immediately, restrict state‑changing endpoints that are vulnerable by using a plugin that enforces nonce checks or by disabling unnecessary admin pages.
  • Enforce two‑factor authentication for administrative accounts and apply least‑privilege principles to user roles to limit potential damage from a forgery attack.

Generated by OpenCVE AI on October 2, 2026 at 20:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Webriti Wallstreet wallstreet allows Cross Site Request Forgery.This issue affects Wallstreet: from n/a through 2.8.6.
Title WordPress Wallstreet theme <= 2.8.6 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-02T20:13:21.126Z

Reserved: 2026-04-07T10:58:29.177Z

Link: CVE-2026-39718

cve-icon Vulnrichment

Updated: 2026-10-02T20:13:13.964Z

cve-icon NVD

Status : Received

Published: 2026-10-02T20:17:02.420

Modified: 2026-10-02T21:16:55.153

Link: CVE-2026-39718

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T20:30:16Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)