Impact
The Time Sheets WordPress plugin is vulnerable to Cross‑Site Request Forgery in all releases up to and including 2.1.3. The flaw stems from missing or incorrect nonce validation on several endpoints, allowing an unauthenticated attacker to forge requests. An adversary could trick a site administrator into clicking a link or otherwise triggering a request that the plugin will process, leading to a variety of administrative actions without the administrator’s explicit consent. The impact is confined to the specific actions exposed by the plugin’s endpoints; it does not grant arbitrary code execution, elevate privileges, or directly compromise data integrity beyond the permitted operations.
Affected Systems
The vulnerability affects the WordPress plugin known as Time Sheets, developed by mrdenny, for any installation using a version of 2.1.3 or earlier. Administrators running these versions should verify the plugin version on their sites.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, and an EPSS score of less than 1% suggests that exploitation of this weakness is unlikely in the broader attack landscape. The vulnerability is not listed in the CISA KEV catalog. Evasion requires an unauthenticated attacker to lure a legitimate administrator into performing a specific action, such as clicking a crafted link. This user‑interaction prerequisite significantly limits the practicality of exploitation.
OpenCVE Enrichment