Impact
The vulnerability in the Generate Post Thumbnails plugin allows an attacker to trick a logged‑in WordPress user into performing actions on behalf of that user. Because the plugin does not verify a CSRF token before processing requests, the attacker can trigger the plugin’s thumbnail generation routine and other authenticated actions without the user’s consent, potentially leading to unauthorized content manipulation. This weakness is identified as CWE‑352.
Affected Systems
Affected systems include the WordPress plugin Generate Post Thumbnails released by marynixie. Versions from the earliest release up through 0.8 are vulnerable. Any site that has installed this plugin and has not applied a newer, patched version is at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk, and the EPSS score of less than 1% suggests that the likelihood of widespread exploitation is low at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is typically via a malicious web page that causes the victim’s browser to submit a forged request to the plugin while the victim is authenticated. Because no active exploit is documented, an attacker would need to entice a user to visit a crafted URL or embed a malicious link in a trusted site.
OpenCVE Enrichment
EUVD