Impact
The vulnerability is a Cross‑Site Request Forgery flaw that allows an attacker to force an authenticated user to perform unwanted actions through the Önceki Yazı Link plugin. This weakness exploits the lack of proper CSRF protection and can modify, delete, or otherwise manipulate content without the user’s consent, potentially compromising the integrity of the site’s data.
Affected Systems
The issue affects the Musa AVCI Önceki Yazı Link plugin versions from the initial release through version 1.3 sent to WordPress installations. Any site running this plugin during that period is potentially exposed.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk, and the EPSS score of <1% suggests that exploitation is unlikely but still possible. The vulnerability is not listed in CISA’s KEV catalog, and no public exploit is known. The likely attack path involves an attacker surreptitiously delivering a crafted request to an authenticated user’s browser, relying on insufficient CSRF safeguards. The impact is limited to the authenticated user’s privileges, but it can lead to unintended content changes or deletion.
OpenCVE Enrichment
EUVD