Cross-site request forgery in WordPress - #VU151465
Published: September 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to install and preview an inactive theme from WordPress.org.
The vulnerability exists due to cross-site request forgery in the theme installation and preview functionality when an administrator opens a specially crafted URL and logs in when prompted. A remote attacker can trick an administrator into opening a specially crafted URL to install and preview an inactive theme from WordPress.org.
The installed theme remains inactive, but is fully loaded for preview.