Cross-site request forgery in WordPress - #VU151465

 

Cross-site request forgery in WordPress - #VU151465

Published: September 20, 2026


Vulnerability identifier: #VU151465
CSH Severity: Medium
CVSS v4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to install and preview an inactive theme from WordPress.org.

The vulnerability exists due to cross-site request forgery in the theme installation and preview functionality when an administrator opens a specially crafted URL and logs in when prompted. A remote attacker can trick an administrator into opening a specially crafted URL to install and preview an inactive theme from WordPress.org.

The installed theme remains inactive, but is fully loaded for preview.


Affected software

WordPress

Remediation

Install security update from vendor's website.

WordPress - addressed in versions 4.8.31, 4.9.32, 5.0.28, 5.1.25, 5.2.27, 5.3.24, 5.4.22, 5.5.21, 5.6.20, 5.7.18, 5.8.16, 5.9.17, 6.0.15, 6.1.13, 6.2.12, 6.3.11, 6.4.11, 6.5.11, 6.6.8, 6.7.8, 6.8.9, 6.9.8, 7.0.5, 7.1.1

External References

Related Security Bulletins