Impact
This vulnerability is a Cross‑Site Request Forgery flaw in the Grand Tour theme that allows an attacker to force a logged‑in user to submit forged requests, potentially causing unintended changes to theme settings or site content. The flaw stems from missing CSRF token validation when processing theme options, enabling arbitrary state changes without direct access to the site administrator account.
Affected Systems
The Grand Tour theme from ThemeGoods, affecting all releases up to and including version 5.5.1.
Risk and Exploitability
The CVSS base score of 5.4 indicates moderate risk. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog, so there is no evidence of active exploitation. The likely attack vector involves a malicious site tricking an authenticated user to visit a crafted URL, which then submits a forged request to the Grand Tour options endpoint, potentially altering theme configuration or other site content.
OpenCVE Enrichment