← WordPress Vulnerabilities
WordPress security by component

Grand Tour

Grand Tour (grandtour) is a WordPress theme with 2 published CVE records in this archive. The latest tracked vulnerability was published Sep 02, 2026; the highest published CVSS base score is 7.1.

Theme slug: grandtour

CVE-2026-66652: Grand Tour actions can be induced through cross-site requests

Grand Tour through 5.5.1 does not adequately protect an affected state-changing operation from cross-site request forgery. An external attacker can cause an interacting logged-in user to submit that request with the victim's WordPress privileges.

PublishedSep 02, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for grandtour
Safe version
Sep 02, 2026 CVE-2026-66652
Grand Tour actions can be induced through cross-site requests
Grand Tour through 5.5.1 does not adequately protect an affected state-changing operation from cross-site request forgery. An external attacker can cause an interacting logged-in user to submit that request with the victim's WordPress privileges.
See mitigation notes
CVE5.4
NVDPending
Jan 22, 2026 CVE-2025-67952
Grand Tour: Cross-site scripting
Grand Tour is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending