Impact
Cross‑Site Request Forgery (CSRF) in the Attire Blocks plugin allows an attacker to cause a victim’s browser to submit requests to the WordPress site with the victim’s credentials. This can lead to unauthorized changes to content, settings, or the site’s configuration. The flaw is caused by insufficient CSRF token validation on forms and actions handled by the plugin.
Affected Systems
The vulnerability affects all releases of the Attire Blocks plugin for WordPress provided by Shafaet Alam, from the first available version through version 1.9.6. Any WordPress installation using one of these versions is susceptible.
Risk and Exploitability
The CVSS base score of 4.3 indicates low‑to‑moderate severity. An EPSS score of less than 1 % suggests a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a malicious web page or phishing message that lures an authenticated user to visit a crafted URL, which then executes the unauthenticated CSRF request using the user’s browser session.
OpenCVE Enrichment
EUVD