WordPress Vulnerabilities
WP < 7.1.1 - Theme Installation via CSRF
Description
WordPress does not properly handle a parameter of the theme installer screen in some cases, which could allow attackers to make a logged in administrator install a theme from the WordPress.org directory via a crafted link.
Affects WordPress
References
Classification
Type
CSRF
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
paulos__
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-17 (about 22 days ago)
Added
2026-09-18 (about 21 days ago)
Last Updated
2026-09-18 (about 21 days ago)