Impact
The vulnerability is a cross-site request forgery flaw in the Wow-Company Bubble Menu – circle floating menu plugin for WordPress, affecting all releases through 4.0.2. The flaw permits an attacker to forge authorized requests on behalf of a logged-in user, potentially performing any actions the user is permitted to execute, such as modifying plugin settings or sending newsletters, leading to unauthorized modification of site behavior. This weakness is identified as CWE-352.
Affected Systems
The affected product is the WordPress Bubble Menu – circle floating menu plugin supplied by Wow-Company, with all versions up to and including 4.0.2 susceptible. Administrators should verify whether their sites are running any of these vulnerable versions.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while an EPSS below 1% suggests a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, because the attack is carried out via a malicious website or social-engineering trick that targets authenticated users, the risk of exploitation remains real for sites that retain older plugin versions and have active users. Prompt remediation reduces the window of opportunity for potential attackers.
OpenCVE Enrichment
EUVD