PT-2026-52825 · WordPress · Child Theme Wizard

·

CVE-2026-57655

·

Published

2026-06-26

·

Updated

2026-06-28

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Child Theme Wizard versions 1.4 and earlier
Description An unauthenticated Cross Site Request Forgery (CSRF) exists, which allows attackers to force users to execute unwanted actions. CSRF is a type of attack that tricks a victim into submitting a malicious request. It occurs when a web application does not properly verify that the request was intentionally initiated by the user.
Recommendations Update to a version newer than 1.4.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57655

Affected Products

Child Theme Wizard