Impact
A flaw in the Easyfonts plugin for WordPress enables Cross‑Site Request Forgery. An attacker can supply a specially crafted request that is accepted by the plugin without proper validation, allowing the attacker to perform actions on behalf of an authenticated user. This weakness permits malicious manipulation of data or settings controlled by the victim’s WordPress account, potentially altering site content or configuration.
Affected Systems
This vulnerability affects the Uzair Easyfonts plugin for WordPress at versions 1.1.2 and earlier. No CPE strings are listed, but the CNA product name provides the necessary vendor information for patching or disabling the plugin.
Risk and Exploitability
The CVSS score of 4.3 places the issue in the low–medium severity range, and the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, suggesting it has not been widely exploited yet. Likely attack vectors involve a user visiting a crafted URL or page that triggers the vulnerable request while the user remains authenticated to the site. The required conditions are the presence of a logged‑in WordPress user with sufficient privileges and exploitation of the unprotected action in Easyfonts.
OpenCVE Enrichment
EUVD