CVE-2026-66652: WordPress Grand Tour theme <= 5.5.1 - Cross Site Request Forgery (CSRF) vulnerability
Published Sep 2, 2026
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Tour allows Cross Site Request Forgery.
This issue affects Grand Tour: from n/a through 5.5.1.
Affected Software
1 affected component
ThemeGoods Grand Tour<=5.5.1
Event History
Sep 2, 2026
CVE Published
via MITRE·11:50 AM
Data Sourced
via MITRE·11:50 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does an attacker need an account on the affected WordPress site?
No. The vulnerability is rated PR:N, indicating that attacker privileges are not required.
2
Is user interaction required for exploitation?
Yes. The UI:R rating indicates that exploitation requires interaction from a user, such as causing them to make a request while authenticated to the site.
3
What is the potential impact if exploitation succeeds?
The supplied severity vector indicates low impact to integrity and availability, with no confidentiality impact. The vulnerability is rated medium severity with a CVSS score of 5.4.
4
Which installations should be considered affected?
Grand Tour versions through 5.5.1 are identified as affected. The available data does not provide a lower version bound.