Impact
Based on the description, it is inferred that the plugin’s lack of proper request validation allows Cross‑Site Request Forgery, which can enable an attacker to trick a victim into initiating unintended actions within the WordPress site.
Affected Systems
The vulnerability affects the PixelYourSite – Your smart PIXEL (TAG) Manager plugin version 10.0.1.2 and all earlier releases, installed on WordPress platforms that have not applied the available patch.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score of less than 1% signals low likelihood of exploitation today; however, the vulnerability is not yet listed in KEV. Based on the description, the likely attack vector involves an authenticated user session where the attacker submits forged requests via a malicious webpage or email, and the plugin accepts the request without verifying a CSRF token.
OpenCVE Enrichment
EUVD