CVE-2026-39718: WordPress Wallstreet theme <= 2.8.6 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Webriti Wallstreet wallstreet allows Cross Site Request Forgery.This issue affects Wallstreet: from n/a through 2.8.6.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The CVSS vector indicates network-based exploitation with low attack complexity and no attacker privileges required. Exploitation does require user interaction, meaning a target user must be induced to perform an action such as visiting attacker-controlled content while authenticated.
Which installations are affected?
Webriti Wallstreet versions through 2.8.6 are affected. The available data does not identify a fixed version or any configuration prerequisite.
What is the potential impact of successful exploitation?
The supplied severity vector rates confidentiality, integrity, and availability impact as high, with scope unchanged. The specific administrative actions that could be forced through CSRF are not provided.