Impact
The vulnerability is a Cross-Site Request Forgery flaw in the Regios MyAnime Widget plugin that permits an attacker to elevate privileges. Once a successful CSRF request is performed, an attacker can perform actions normally restricted to administrators, such as modifying widget settings or publishing content without proper authorization.
Affected Systems
The flaw affects all installations of Regios MyAnime Widget version 1.0 and earlier. Site owners running the plugin in any WordPress environment should verify their plugin version and update accordingly.
Risk and Exploitability
With a CVSS score of 8.8, the vulnerability is considered high severity. While the EPSS score is below 1 %, indicating a low probability of exploitation in the wild at present, the lack of a KEV listing does not diminish the potential risk to sites that remain vulnerable. Attackers could exploit the CSRF by enticing an authenticated user to visit a crafted URL or by embedding malicious content within a legitimate page, thereby tricking the user into triggering privileged actions without their knowledge.
OpenCVE Enrichment
EUVD