Impact
A CSRF flaw exists in the Abu Bakar TWB Woocommerce Reviews WordPress plugin that enables a malicious site to trigger review‑related actions on a vulnerable e‑commerce site. By exploiting the lack of proper request origin validation, an attacker can cause an authenticated user to submit or modify reviews without the user’s intent, leading to undesirable changes in the site’s content or user interactions. The defect is classified as CWE‑352.
Affected Systems
The vulnerability affects all releases of the TWB Woocommerce Reviews plugin up to and including version 1.7.7. Any WordPress installation that has this plugin installed in a vulnerable version is at risk.
Risk and Exploitability
The CVSS base score of 4.3 indicates moderate severity. The EPSS score of less than 1 % suggests exploitation is currently unlikely, and the vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that a successful attack requires the victim to be authenticated and to visit a crafted page that submits a request to the vulnerable endpoint. The attacker’s attacker could then trigger unintended review‑related actions on the site.
OpenCVE Enrichment
EUVD