Impact
The vulnerability is a Cross Site Request Forgery (CSRF) flaw that allows an attacker to trick an authenticated user into performing unintended actions within the WordPress site. As a result, an attacker could manipulate the store’s configuration, permissions, or data without the user’s consent, which is a typical CSRF weakness classified under CWE‑352.
Affected Systems
Applicable to the silverplugins217 Build Private Store For Woocommerce WordPress plugin in all releases from the earliest version up to and including 1.0. Users of any of these versions are potentially impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates a low to moderate severity. The EPSS score of < 1% suggests a very low likelihood that the vulnerability is currently exploited in the wild, and the vulnerability is not listed in the CISA KEV catalog. Inferred evidence points to a remote or user‑based attack vector, likely requiring that the victim be logged into an account with sufficient privileges to perform configuration changes through the plugin’s interface. The attack would succeed if the victim submits a crafted request that bypasses CSRF protection mechanisms.
OpenCVE Enrichment
EUVD