VYPR
Medium severity5.4NVD Advisory· Published Apr 8, 2026· Updated Apr 29, 2026

CVE-2026-39635

CVE-2026-39635

Description

Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Magazine grandmagazine allows Cross Site Request Forgery.This issue affects Grand Magazine: from n/a through <= 3.5.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Cross-Site Request Forgery (CSRF) vulnerability in Grand Magazine theme ≤3.5.5 allows attackers to force privileged users into unwanted actions.

Vulnerability

Overview The Grand Magazine WordPress theme, versions 3.5.5 and below, is affected by a Cross-Site Request Forgery (CSRF) vulnerability [1]. This security flaw stems from insufficient validation of requests made to the theme's administrative functions, allowing an attacker to craft malicious requests that execute unintended actions on behalf of an authenticated administrator.

Exploitation

Method To exploit this CSRF, an attacker must trick a privileged user (e.g., an administrator) into clicking a malicious link or visiting a crafted web page while authenticated to the WordPress site [1]. The attack requires no special privileges but relies on social engineering to trigger the forged request. No authentication is needed by the attacker themselves; the victim's active session provides the necessary credentials.

Impact

Successful exploitation could enable an attacker to perform unauthorized actions within the theme's settings, such as altering configurations, injecting malicious content, or other administrative operations [1]. The CVSS score of 5.4 indicates moderate severity, highlighting the potential for significant disruption if leveraged in mass-exploit campaigns.

Mitigation

The vendor has not yet released a patch for this vulnerability as of the publication date [1]. Users are urged to update the theme immediately once a fixed version becomes available. Until then, administrators should exercise caution with links and requests, and consider implementing additional CSRF protections or using a Web Application Firewall (WAF) as a temporary workaround.

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.