CVE-2026-39603: WordPress Grand Photography theme <= 5.7.8 - Cross Site Request Forgery (CSRF) vulnerability
Published Apr 8, 2026
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Photography grandphotography allows Cross Site Request Forgery.This issue affects Grand Photography: from n/a through <= 5.7.8.
Affected Software
1 affected component
ThemeGoods Grand Photography<=5.7.8
Event History
Apr 8, 2026
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-39603?
The severity of CVE-2026-39603 is medium with a CVSS score of 5.4.
2
What type of vulnerability is CVE-2026-39603?
CVE-2026-39603 is a Cross Site Request Forgery (CSRF) vulnerability.
3
Which versions of the Grand Photography theme are affected by CVE-2026-39603?
CVE-2026-39603 affects Grand Photography theme versions from n/a through 5.7.8.
4
How do I fix CVE-2026-39603?
To fix CVE-2026-39603, you should update the Grand Photography theme to the latest version.
5
What impact does CVE-2026-39603 have on users?
CVE-2026-39603 may allow unauthorized actions to be performed on behalf of users without their consent.