Description
Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.
Published: 2026-07-23
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated Cross‑Site Request Forgery (CWE‑352) affecting the ApusListing theme up to version 1.2.63. An attacker can induce an already‑logged‑in user to submit a crafted request, causing the site to perform privileged actions under that user's identity.

Affected Systems

All WordPress installations that use the ApusTheme ApusListing theme with versions 1.2.63 or earlier are impacted. The patch is available in version 1.2.64 and later, which removes the vulnerable code path. No further product or vendor extensions are mentioned in the data.

Risk and Exploitability

The CVSS score of 8.8 places this flaw in the Severe category, while the EPSS score of less than 1% indicates a low but non‑zero current exploitation probability. Because the attack vector is web‑based and requires only that a legitimate user be tricked into visiting a crafted request, it is feasible for opportunistic attackers. It is not listed in the CISA KEV catalog, so no mass exploitation indicators are reported yet.

Generated by OpenCVE AI on August 4, 2026 at 15:28 UTC.

Remediation

Vendor Solution

Update the WordPress ApusListing theme to the latest available version (at least 1.2.64).


OpenCVE Recommended Actions

  • Update the ApusListing theme to version 1.2.64 or newer.
  • Add or enforce cryptographically signed nonces on all state‑changing forms and AJAX endpoints to prevent CSRF attacks.
  • Temporarily disable or remove the ApusListing theme until a patched version is available.

Generated by OpenCVE AI on August 4, 2026 at 15:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Apustheme
Apustheme apuslisting
Wordpress
Wordpress wordpress
Vendors & Products Apustheme
Apustheme apuslisting
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.
Title WordPress ApusListing theme <= 1.2.63 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Apustheme Apuslisting
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T14:23:47.952Z

Reserved: 2026-06-25T08:04:53.458Z

Link: CVE-2026-57785

cve-icon Vulnrichment

Updated: 2026-07-23T14:23:43.860Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:30.540

Modified: 2026-07-23T15:17:21.920

Link: CVE-2026-57785

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:30:06Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)