Impact
The vulnerability is a classic Cross‑Site Request Forgery flaw in the fuzzoid 3DPrint Lite WordPress plugin. It allows an attacker to harness an authenticated user's session to trigger unintended actions within the plugin, potentially leading to unauthorized changes or data manipulation. The flaw stems from missing or inadequate CSRF protections, which is reflected in CWE‑352.
Affected Systems
All installations of the 3DPrint Lite plugin for WordPress up to and including version 2.1.3.5 are affected. The plugin is distributed by fuzzoid and does not provide a version number before the documented 2.1.3.5 release. WordPress sites running any of these versions should be treated as vulnerable.
Risk and Exploitability
The CVSS score of 4.3 rates the vulnerability as medium severity, while the EPSS score of less than 1 % indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no known high‑profile attacks. Based on the description, it is inferred that exploitation would likely require the victim to be logged into the WordPress administrative interface and to click a specially crafted URL or interact with a malicious site, forming the classic CSRF attack vector.
OpenCVE Enrichment
EUVD