Impact
The Moderate Selected Posts WordPress plugin contains a Cross‑Site Request Forgery flaw caused by missing nonce verification in the admin page handler. This weakness allows an attacker to craft a forged request that, when executed by a site administrator who follows a malicious link, will change the plugin’s configuration. The outcome is that an attacker can alter or disable settings set by the administrator, potentially weakening site security or other plugin functions.
Affected Systems
WordPress sites that use the Moderate Selected Posts plugin version 1.4 or older, released by hallsofmontezuma. The vulnerability is present in all versions up to and including 1.4, regardless of the WordPress core version.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score of < 1% shows that while the probability of exploitation is very low, attacks are still possible. The flaw is not listed in CISA KEV. An attacker would need to lure a website administrator into clicking a crafted link or otherwise submitting a forged request. No special privileges are required beyond the admin role, and no additional system access is needed, making the attack path relatively straightforward for a social engineering vector.
OpenCVE Enrichment