Impact
A Cross‑Site Request Forgery vulnerability exists in the AI WP Writer plugin for WordPress, affecting all releases up to and including 3.8.4.4. The flaw, identified as CWE‑352, allows an attacker to cause an authenticated user to submit forged requests to the plugin, potentially executing actions that the user did not intend, such as creating, editing or deleting content or managing plugin settings, thereby compromising the integrity of the site.
Affected Systems
The vulnerability is limited to installations of the AI WP Writer plugin from a version prior to 3.8.4.5, regardless of the WordPress core version. Any site running a supported WordPress installation with a vulnerable AI WP Writer plugin is at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not catalogued in the CISA KEV list. An attacker can exploit it by sending a crafted request to the plugin's processing endpoint; the request must be made while the target user is authenticated. Because no privilege escalation is required beyond the victim's session, the impact is confined to the permissions of the logged‑in user, but can include data tampering or destruction.
OpenCVE Enrichment
EUVD