CVE-2026-39634: WordPress Grand Portfolio theme <= 3.3 - Cross Site Request Forgery (CSRF) vulnerability
Published Apr 8, 2026
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Portfolio grandportfolio allows Cross Site Request Forgery.This issue affects Grand Portfolio: from n/a through <= 3.3.
Affected Software
1 affected component
ThemeGoods Grand Portfolio<=3.3
Event History
Apr 8, 2026
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-39634?
CVE-2026-39634 has a medium severity rating of 5.4 according to the CVSS 3.1 scoring system.
2
How can I fix CVE-2026-39634?
To fix CVE-2026-39634, update the ThemeGoods Grand Portfolio to the latest version above 3.3.
3
What type of vulnerability is CVE-2026-39634?
CVE-2026-39634 is a Cross-Site Request Forgery (CSRF) vulnerability.
4
Which version of the Grand Portfolio theme is affected by CVE-2026-39634?
CVE-2026-39634 affects the Grand Portfolio theme versions from its release up to and including version 3.3.
5
Who is the vendor for the software related to CVE-2026-39634?
The vendor for the software related to CVE-2026-39634 is ThemeGoods.