Impact
A cross‑site request forgery flaw in the MyBookTable Bookstore plugin allows an attacker to trigger authenticated actions on the site without the user’s knowledge. The weakness, identified as CWE‑352, results from insufficient verification that incoming requests originate from legitimate sources.
Affected Systems
WordPress sites running the zookatron MyBookTable Bookstore plugin version 3.5.3 or earlier. No other products are listed as affected.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity, and the EPSS score of less than 1% suggests exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Because the flaw is a CSRF vulnerability, an attacker would normally need to entice an authenticated user into sending a malicious request; this inference is based on the description. Consequently, the risk remains moderate but could materialize in environments where users are exposed to phishing or social engineering attempts.
OpenCVE Enrichment
EUVD