SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-66652

MEDIUM · CVSS 5.4 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A Cross-Site Request Forgery (CSRF) vulnerability in the Grand Tour theme allows attackers to perform unauthorized actions on behalf of authenticated users. This could lead to unauthorized changes or data exposure, impacting the integrity of user accounts. Organizations using versions up to 5.5.1 of the Grand Tour theme should prioritize patching this vulnerability to mitigate potential exploitation risks.

CVE
CVE-2026-66652
Severity
MEDIUM
CVSS
5.4
EPSS
0.10%

Original NVD Description

Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Tour allows Cross Site Request Forgery. This issue affects Grand Tour: from n/a through 5.5.1.