WordPress has a public API... several of them, in fact. A theme doesn't use those, it makes direct calls to internal WP code, and it uses WordPress internal data structures. This is enough to make it a derivative work.
From http://www.gnu.org/licenses/old-licenses/gpl-2.0-faq.html#Me... :
"Combining two modules means connecting them together so that they form a single larger program. If either part is covered by the GPL, the whole combination must also be released under the GPL—if you can't, or won't, do that, you may not combine them.
What constitutes combining two parts into one program? This is a legal question, which ultimately judges will decide. We believe that a proper criterion depends both on the mechanism of communication (exec, pipes, rpc, function calls within a shared address space, etc.) and the semantics of the communication (what kinds of information are interchanged).
If the modules are included in the same executable file, they are definitely combined in one program. If modules are designed to run linked together in a shared address space, that almost surely means combining them into one program.
By contrast, pipes, sockets and command-line arguments are communication mechanisms normally used between two separate programs. So when they are used for communication, the modules normally are separate programs. But if the semantics of the communication are intimate enough, exchanging complex internal data structures, that too could be a basis to consider the two parts as combined into a larger program."
Ultimately, it is a matter of interpretation, but all previous interpretation, including those made in courts of law, pretty much universally agree with Matt on this one. It's very difficult to consider a theme to be a "separate program" when it's deep-linking to internal functions and data structures and it also cannot run independently.