Impact
This vulnerability allows attackers to exploit Cross Site Request Forgery against the Subscription Renewal Reminders for WooCommerce plugin, potentially executing actions on behalf of a victim without their consent. The impact is the unauthorized execution of plugin functions such as changing subscription settings or triggering other privileged operations. The weakness is identified as Cross‑Site Request Forgery (CWE‑352).
Affected Systems
Affected systems include the storepro Subscription Renewal Reminders for WooCommerce WordPress plugin, versions from any release up to and including 1.4.1. The vulnerability is present in all these releases, regardless of installation method.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk level. The EPSS score of less than 1% suggests the probability of exploitation is very low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an unauthenticated CSRF request that leverages a crafted link or form submission; an attacker does not need special permissions or additional conditions beyond the presence of the vulnerable plugin.
OpenCVE Enrichment
EUVD