Impact
The vulnerability is a CSRF flaw in the Theme Options Z plugin that permits an attacker to persuade a logged‑in user to submit requests that perform privileged actions without the user’s consent. When activated, the attacker can change plugin settings or otherwise manipulate the site state, compromising configuration integrity and potentially enabling further strategic attacks.
Affected Systems
It affects installations of the Theme Options Z WordPress plugin up to and including version 1.4. Users running any of those versions on WordPress sites are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.4 categorizes the flaw as moderate. The EPSS score of less than 1% indicates a very low probability of real‑world exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a user to have an authenticated session with the site and to visit an attacker‑controlled page that submits a crafted request, so the attack vector is inferred to be a malicious webpage or email. The risk remains limited but non‑negligible in environments with many active users or where the plugin performs critical configuration tasks.
OpenCVE Enrichment
EUVD