CVE-2026-24961: WordPress Grand Blog theme < 3.1.5 - Server Side Request Forgery (SSRF) vulnerability
Published Feb 3, 2026
·Updated
Server-Side Request Forgery (SSRF) vulnerability in ThemeGoods Grand Blog grandblog allows Server Side Request Forgery.This issue affects Grand Blog: from n/a through < 3.1.5.
Affected Software
1 affected component
ThemeGoods Grand Blog<3.1.5
Event History
Feb 3, 2026
CVE Published
via MITRE·02:08 PM
Data Sourced
via MITRE·02:08 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-24961?
CVE-2026-24961 is classified as a critical severity vulnerability due to its potential for unauthorized access and exploitation.
2
How do I fix CVE-2026-24961?
To fix CVE-2026-24961, you should update your Grand Blog theme to version 3.1.5 or later.
3
What does CVE-2026-24961 affect?
CVE-2026-24961 affects versions of the Grand Blog theme prior to 3.1.5.
4
What type of vulnerability is CVE-2026-24961?
CVE-2026-24961 is a Server-Side Request Forgery (SSRF) vulnerability.
5
Who is the vendor associated with CVE-2026-24961?
The vendor associated with CVE-2026-24961 is ThemeGoods.