Impact
The IMAQ Core plugin contains a Cross‑Site Request Forgery vulnerability that allows an unauthenticated attacker to change the plugin’s URL structure settings. The flaw arises from missing nonce verification during the update process, enabling a forged request to execute when an administrator clicks a malicious link. This weakness permits the attacker to alter how the plugin rewrites URLs, potentially disrupting site navigation or redirecting traffic.
Affected Systems
WordPress sites running IMAQ Core 1.2.1 or earlier are affected. The plugin is issued by imaqpress under the product name IMAQ CORE. No specific version numbers beyond 1.2.1 are mentioned as vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates low‑medium severity, and the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. An attacker can exploit this weakness by directing a site administrator to visit a crafted link that submits a CSRF request to update the URL structure settings. Because the attacker need not authenticate, the impact is limited to the scope of the plugin’s configuration, but it could disturb site functionality or enable further damage if other plugin settings are affected.
OpenCVE Enrichment