CVE-2026-39633: WordPress Grand Car Rental theme <= 3.6.9 - Cross Site Request Forgery (CSRF) vulnerability
Published Apr 8, 2026
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Car Rental grandcarrental allows Cross Site Request Forgery.This issue affects Grand Car Rental: from n/a through <= 3.6.9.
Affected Software
1 affected component
ThemeGoods Grand Car Rental<=3.6.9
Event History
Apr 8, 2026
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-39633?
The severity of CVE-2026-39633 is medium, with a CVSS score of 6.5.
2
How do I fix CVE-2026-39633?
To fix CVE-2026-39633, update the Grand Car Rental theme to version 3.7.0 or later.
3
What is the impact of CVE-2026-39633?
CVE-2026-39633 allows unauthorized actions to be performed on behalf of authenticated users due to a Cross Site Request Forgery vulnerability.
4
Which versions of the Grand Car Rental theme are affected by CVE-2026-39633?
CVE-2026-39633 affects all versions of the Grand Car Rental theme from n/a through version 3.6.9.
5
Who is affected by CVE-2026-39633?
Users of the Grand Car Rental theme prior to version 3.7.0 are affected by CVE-2026-39633.