CVE-2026-39635: WordPress Grand Magazine theme <= 3.5.5 - Cross Site Request Forgery (CSRF) vulnerability
Published Apr 8, 2026
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Magazine grandmagazine allows Cross Site Request Forgery.This issue affects Grand Magazine: from n/a through <= 3.5.5.
Affected Software
1 affected component
ThemeGoods Grand Magazine<=3.5.5
Event History
Apr 8, 2026
CVE Published
via MITRE·08:30 AM
Data Sourced
via MITRE·08:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-39635?
The severity of CVE-2026-39635 is rated medium with a score of 5.4.
2
How do I fix CVE-2026-39635?
To fix CVE-2026-39635, update the Grand Magazine theme to version 3.5.6 or later.
3
What type of vulnerability is CVE-2026-39635?
CVE-2026-39635 is a Cross Site Request Forgery (CSRF) vulnerability affecting the Grand Magazine theme.
4
Which versions of Grand Magazine are affected by CVE-2026-39635?
CVE-2026-39635 affects Grand Magazine theme versions from n/a through 3.5.5.
5
Who is the vendor associated with CVE-2026-39635?
The vendor associated with CVE-2026-39635 is ThemeGoods, the creator of the Grand Magazine theme.