Impact
A Cross‑Site Request Forgery vulnerability (CWE‑352) exists in the mg12 Mobile Themes plugin for WordPress. The flaw enables an attacker to trick an authenticated user into submitting unwanted requests that the plugin processes, potentially changing site settings or content. No specific data‑loss details are supplied, so the described impact is inferred from typical CSRF consequences.
Affected Systems
WordPress installations that have the Mobile Themes plugin (mg12 Mobile Themes) at version 1.1.1 or earlier are affected.
Risk and Exploitability
The CVSS score of 4.3 reflects low‑to‑medium severity, and the EPSS score of less than 1% indicates a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to convince an authenticated user to visit a malicious page or click a crafted link that triggers the plugin’s request handling logic.
OpenCVE Enrichment
EUVD