CVE-2026-39617: WordPress Bluestreet theme <= 1.7.3 - Cross Site Request Forgery (CSRF) to Arbitrary Plugin Installation vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bluestreet allows Cross Site Request Forgery.This issue affects Bluestreet: from n/a through <= 1.7.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Bluestreet theme (bluestreet)to a version that resolves this vulnerability.Fixed in 1.7.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39617?
CVE-2026-39617 is a high-severity vulnerability that allows for Cross Site Request Forgery (CSRF) attacks to result in arbitrary plugin installations.
How do I fix CVE-2026-39617?
To fix CVE-2026-39617, update the Bluestreet theme to the latest version that addresses this CSRF vulnerability.
What are the potential impacts of CVE-2026-39617?
CVE-2026-39617 can lead to unauthorized users installing malicious plugins, which may compromise the security of the WordPress site.
Who is affected by CVE-2026-39617?
CVE-2026-39617 affects users of the Bluestreet theme version 1.7.3 or earlier.
Is CVE-2026-39617 a widespread vulnerability?
The prevalence of CVE-2026-39617 depends on the popularity of the Bluestreet theme among WordPress users.