Impact
The Posts Navigation Links for Sections and Headings – Free by WP Masters plugin for WordPress is affected by a Cross‑Site Request Forgery vulnerability. The flaw stems from missing or incorrect nonce validation on the 'wpm_navigation_links_settings' page, allowing unauthenticated attackers to forge requests that update plugin settings when an administrator follows a crafted link. This can result in unauthorized configuration changes, potentially altering navigation behaviour or exposing other weaknesses if the plugin interacts with sensitive data.
Affected Systems
WordPress sites running the Posts Navigation Links for Sections and Headings – Free by WP Masters plugin version 1.0.1 or earlier are impacted. The plugin is distributed under the WP Masters brand and is installed via the WordPress plugin repository.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score of less than 1% reflects a very low probability of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. Attackers would need to persuade an authenticated administrator to click a malicious link; the vulnerability is not exploitable by remote code execution or arbitrary data disclosure.
OpenCVE Enrichment