Impact
The vulnerability is a Cross‑Site Request Forgery flaw in the Football Pool plugin that allows an attacker to change the plugin’s settings without proper authorization. The flaw is classified as CWE‑352. The description does not specify any direct data disclosure or code execution capabilities, only that configuration values can be altered when a request is forged.
Affected Systems
WordPress Football Pool plugin (AntoineH) versions up to 2.12.2 are affected. The issue spans all releases from the initial version through 2.12.2.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests exploitation is currently unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. It is inferred from typical CSRF patterns that exploitation would involve a user being tricked into submitting a forged request to the plugin’s settings endpoint; however, the description does not provide explicit details about the required conditions or attack vector.
OpenCVE Enrichment
EUVD