Impact
The vulnerability is a Cross‑Site Request Forgery flaw in the Shahjahan Jewel FluentSMTP WordPress plugin that allows an attacker to forge requests sent by an authenticated user; the description does not specify the concrete operations that could be performed but the lack of CSRF safeguards means any action the plugin accepts could be invoked without the user’s intent.
Affected Systems
All installations of the Shahjahan Jewel "FluentSMTP" plugin for WordPress running version 2.2.80 or earlier are affected; there are no other vendors or products listed as impacted.
Risk and Exploitability
The CVSS score of 4.3 points to a low to moderate severity, and the EPSS rating of < 1% indicates a very low probability of exploitation at present; the vulnerability is not in the CISA KEV catalog. Attackers would need a victim who is authenticated to WordPress and to visit a crafted URL or submit a forged form to trigger the flaw. Based on the CSRF nature of the vulnerability, it is inferred that the attack requires an authenticated user to be tricked into interacting with a malicious URL or form.
OpenCVE Enrichment
EUVD