Impact
The Pretty Url plugin for WordPress contains a CSRF flaw that lets an attacker force an authenticated user’s browser to submit a forged request to the site. This can result in unauthorized changes to URL redirects or settings, potentially giving the attacker a foothold to further manipulate the WordPress installation. The weakness belongs to CWE‑352 and does not directly lead to data loss, but it enables an attacker to execute privileged actions without user interaction.
Affected Systems
The vulnerability affects the faaiq Pretty Url WordPress plugin for all versions up to and including 1.5.5. WordPress sites that have installed this plugin and have users with editing or administrative privileges are potentially impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates a low to moderate severity. The EPSS score of less than 1% reflects a very low probability that the vulnerability will be exploited in the wild, and it is not listed in CISA’s KEV catalog. However, the attack vector is likely through a crafted link or malicious content that tricks an authenticated user into visiting a specially minted URL. While exploitability is low, the impact of unauthorized configuration changes can serve as an escalation path, so the risk is considered non‑negligible for actively managed WordPress sites.
OpenCVE Enrichment
EUVD