Impact
A CSRF flaw exists in the Print PDF Generator and Publisher plugin that allows an attacker to trick a privileged WordPress user into performing unintended actions such as generating PDFs or publishing content. The vulnerability can be leveraged when a user follows a malicious link or submits a crafted request that the plugin fails to properly verify. This flaw can lead to unauthorized data exposure or modification of site content if the plugin performs privileged operations.
Affected Systems
The affected plugin is "Print PDF Generator and Publisher" from the vendor "verkkovaraani". All releases from the initial version up to and including 1.2.0 are affected; any version newer than 1.2.0 has the vulnerability fixed or removed.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, and the EPSS score of less than 1% suggests a low probability of current exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is indirect, whereby an attacker convinces a legitimate user to click a malicious link or submit a crafted request, exploiting the missing CSRF protection.
OpenCVE Enrichment
EUVD