CVE-2026-42705: WordPress Grand News theme <= 3.4 - Broken Access Control vulnerability
Published Oct 10, 2026
·Updated
Unauthenticated Broken Access Control in Grand News <= 3.4 versions.
Affected Software
1 affected component
WordPress Grand News<=3.4
Event History
Oct 10, 2026
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The vulnerability is unauthenticated and has low attack complexity. An attacker does not need credentials or user interaction to attempt exploitation over the network.
2
What is the security impact if exploitation succeeds?
The reported impact is high on integrity, meaning an attacker may be able to make unauthorized changes. No confidentiality or availability impact is indicated by the supplied vector.
3
Which deployments are affected?
WordPress sites using the Grand News theme version 3.4 or earlier are affected according to the advisory data.