PatchSiren

ThemeGoods CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL ThemeGoods CVE published 2026-07-13

CVE-2026-57770

The CVE record for CVE-2026-57770 was published on 2026-07-13T10:16:41.040Z and has not been modified since then. The NVD entry is currently 9.8 CRITICAL. A Deserialization of Untrusted Data vulnerability exists in the Grand Photography theme, allowing for Object Injection. This issue affects Grand Photography versions from n/a through <= 5.7.8. The vulnerability has a high impact due to its critical seve [truncated]

HIGH ThemeGoods CVE published 2026-06-17

CVE-2025-68524

CVE-2025-68524 is a HIGH severity vulnerability (CVSS Score: 7.1) affecting Avante versions prior to 3.0.5. This Unauthenticated Cross Site Scripting (XSS) vulnerability allows attackers to inject malicious scripts into web pages viewed by other users. The vulnerability was published on June 17, 2026, and immediately gained attention due to its potential for exploitation. Users of affected Avante versions [truncated]

HIGH ThemeGoods CVE published 2026-06-17

CVE-2025-69151

CVE-2025-69151 is an Unauthenticated Cross Site Scripting (XSS) vulnerability in Grand Car Rental theme version 3.7 or earlier. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. Users of Grand Car Rental theme version 3.7 or earlier should prioritize patching to prevent potential XSS attacks. The vulnerability allows attackers to inject malicious scripts into the website, poten [truncated]

MEDIUM ThemeGoods CVE published 2026-04-08

CVE-2026-39635

A Cross-Site Request Forgery (CSRF) vulnerability was identified in ThemeGoods Grand Magazine, affecting versions from n/a through <= 3.5.5. This issue allows for Cross Site Request Forgery. The vulnerability's CVSS score is 5.4, categorized under MEDIUM severity. Users should verify their version and apply updates or mitigations as necessary. Limited details are available about specific impacts and explo [truncated]

MEDIUM ThemeGoods CVE published 2026-04-08

CVE-2026-39634

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the Grand Portfolio theme for WordPress. This issue, tracked as CVE-2026-39634, allows attackers to perform Cross Site Request Forgery. The vulnerability affects Grand Portfolio from its inception through version 3.3. The vulnerability has a CVSS score of 5.4 and a severity rating of MEDIUM. It was published on April 8, 2026, and last mod [truncated]

MEDIUM ThemeGoods CVE published 2026-04-08

CVE-2026-39633

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Grand Car Rental theme for WordPress, affecting versions up to and including 3.6.9. This issue allows attackers to perform Cross-Site Request Forgery attacks. The CVE record was published on 2026-04-08T09:16:33.877Z and has not been modified since then. Users of the Grand Car Rental theme for WordPress, particularly those using versions up to [truncated]

MEDIUM ThemeGoods CVE published 2026-04-08

CVE-2026-39632

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the Grand Blog theme, affecting versions up to and including 3.1. This issue allows attackers to perform Cross-Site Request Forgery. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. Users of the Grand Blog theme should be aware of this vulnerability and take necessary precautions to prevent potential attacks.

MEDIUM ThemeGoods CVE published 2026-04-08

CVE-2026-39603

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Grand Photography theme for WordPress, affecting versions up to and including 5.7.8. This issue allows attackers to perform unintended actions on behalf of users. The vulnerability has a CVSS score of 5.4 and a severity rating of MEDIUM. The CVE record was published on 2026-04-08T09:16:29.467Z and last modified on 2026-07-20T20:10:00.110Z.