Impact
The vulnerability is a Cross‑Site Request Forgery flaw in the Giraphix Creative Layouts for Elementor plugin for WordPress. The CVE text indicates that the flaw allows Cross‑Site Request Forgery but does not state any additional consequences. The defect is identified as CWE‑352.
Affected Systems
Giraphix Creative Layouts for Elementor plugin for WordPress. Versions from the first release (no specific start version) up through 1.11 are affected, while later releases are not listed as vulnerable.
Risk and Exploitability
The CVSS score of 4.3 places it in the low‑to‑medium threat range. An EPSS value under 1% suggests a low probability that this flaw will be actively exploited at present. The flaw is not listed in the CISA KEV catalog. The CVE statement does not disclose a specific attack vector or requirement for exploitation, so no further details on how a threat actor might leverage this weakness are available in the public data.
OpenCVE Enrichment
EUVD