Impact
Cross‑Site Request Forgery (CSRF) allows an attacker to cause a logged‑in user to submit unintended requests to the WordPress site. The vulnerability is limited to the Christmas Panda plugin and does not grant code execution or direct access to the server; an attacker could, however, perform any actions that the affected user is authorized to perform, such as changing settings, posting content, or modifying plugin configuration.
Affected Systems
The flaw exists in the pixolette Christmas Panda plugin for WordPress, affecting all versions from the initial release through version 1.0.4. Users running these versions on any WordPress installation are vulnerable.
Risk and Exploitability
With a CVSS score of 4.3 and an EPSS of less than 1%, the exploitation probability is low and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is that an attacker hosts a malicious web page that tricks a logged‑in user into visiting it, triggering the unwanted request. Successful exploitation would rely on the victim’s session cookies and would only be possible if the plugin does not enforce proper CSRF tokens or same‑origin checks.
OpenCVE Enrichment
EUVD