Impact
The vulnerability is a Cross‑Site Request Forgery (CSRF) flaw in the RealMag777 InPost Gallery plugin that allows attackers to send requests on behalf of authenticated users, potentially leading to unintended modifications or deletions of gallery content. The weakness is characterized by CWE‑352.
Affected Systems
RealMag777 InPost Gallery plugin versions up to and including 2.1.4.3 are affected. WordPress sites that have this plugin installed should verify that they are not running a vulnerable version.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% indicates a low but nonzero likelihood of exploitation. The vulnerability is not currently listed in the CISA KEV catalog, suggesting that there are no confirmed active exploits. The attack vector is likely browser‑based, requiring an attacker to trick a user into visiting a malicious site or link that submits a forged request to the plugin’s endpoints.
OpenCVE Enrichment
EUVD