Impact
The vulnerability is a CSRF flaw in the Glance That plugin that can be exploited by sending a crafted request that will be processed by an authenticated user. The described issue allows unauthorized actions to be performed without the user’s consent. While the description does not elaborate beyond CSRF, it is reasonable to infer that an attacker could induce unwanted content changes or other privileged operations within the plugin. The weakness aligns with CWE‑352, indicating inadequate request validation.
Affected Systems
WordPress installations that use the Glance That plugin version 4.9 or earlier. The plugin vendor is uamv:Glance That.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity level. With an EPSS score of less than 1%, the likelihood of exploitation in the wild is low, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to obtain a valid session cookie or persuade an authenticated user to visit a malicious link, implying the attack vector is likely through a malicious website or email that tricks the user into performing an unintended action.
OpenCVE Enrichment
EUVD