Impact
The vulnerability is a CSRF flaw that allows an attacker to elevate a user’s privileges to administrator level by forging state‑changing requests to the WP‑Recall plugin. The flaw arises from improper nonce verification, letting an unauthenticated request alter the user’s role. This is a classic CWE‑352 issue.
Affected Systems
WP‑Recall plugin from any released version up to and including 16.26.14, released by tggfref.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. The EPSS score of < 1% shows a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be a CSRF attack via a crafted link or form, requiring the victim to visit a malicious webpage while authenticated to the WordPress site.
OpenCVE Enrichment
EUVD