Impact
The plugin contains a Cross‑Site Request Forgery flaw that permits an attacker to change configuration settings without the victim's knowledge. The vulnerability is rooted in CWE‑352, because the plugin accepts state mutation requests without validating a CSRF token. If exploited, an attacker could alter menu structure, enable or disable features, or change other contextual settings that might be leveraged for further compromise.
Affected Systems
The flaw affects the Wow‑Company Side Menu Lite WordPress plugin, versions up through 5.3.1. Any installation of the plugin on a WordPress site is susceptible.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate impact. The EPSS value of less than 1 % suggests the likelihood of exploitation is low, and the vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that exploitation requires a victim who is logged in to the site with permission to alter plugin settings and that the attack follows a typical CSRF scenario, where a forged request is automatically authenticated by the browser.
OpenCVE Enrichment
EUVD