CVE-2026-39632: WordPress Grand Blog theme <= 3.1 - Cross Site Request Forgery (CSRF) vulnerability
Published Apr 8, 2026
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Blog grandblog allows Cross Site Request Forgery.This issue affects Grand Blog: from n/a through <= 3.1.
Affected Software
1 affected component
ThemeGoods Grand Blog<=3.1
Event History
Apr 8, 2026
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-39632?
CVE-2026-39632 has a medium severity rating of 6.5 on the CVSS scale.
2
How do I fix CVE-2026-39632?
To mitigate CVE-2026-39632, update the ThemeGoods Grand Blog theme to version 3.2 or later.
3
What type of vulnerability is CVE-2026-39632?
CVE-2026-39632 is a Cross-Site Request Forgery (CSRF) vulnerability.
4
Which versions of Grand Blog are affected by CVE-2026-39632?
CVE-2026-39632 affects ThemeGoods Grand Blog versions from n/a through 3.1.
5
What is the impact of exploiting CVE-2026-39632?
Exploitation of CVE-2026-39632 could allow unauthorized actions to be performed on behalf of authenticated users.