Impact
A Cross‑Site Request Forgery flaw exists in the Auto Tag Links plugin for WordPress up to version 1.0.13. The vulnerability allows an attacker to craft a request that is sent from a victim’s browser while the victim is authenticated, causing the plugin to perform privileged actions without the victim’s consent. The weakness can result in unauthorized modification of site settings or content, potentially compromising the integrity of the affected WordPress site.
Affected Systems
The issue affects all installations of the Free plug in by SEO Roma Auto Tag Links that have a version of 1.0.13 or earlier. No other WordPress plugins or core versions are listed as affected.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score of < 1% shows a very low probability that the flaw will be actively exploited. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a forged HTTP request sent from a victim’s browser, possibly through a malicious link or a compromised site, with the victim authenticated to WordPress. An attacker could trigger configuration changes or other state‑changing operations without the victim’s awareness.
OpenCVE Enrichment
EUVD