Impact
A cross‑site request forgery flaw in the Essential Breadcrumbs plugin allows an attacker to submit crafted requests that execute privileged actions on behalf of an authenticated user. The vulnerability does not specify which actions can be performed, but it provides a pathway for an attacker to elevate privileges within the WordPress site, potentially altering content, settings, or other protected resources.
Affected Systems
The Essential Breadcrumbs plugin sold by Essential Marketer, with any version up to and including 1.1.1, is affected. No other products or higher versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity issue, while the EPSS score of less than 1% suggests that widespread exploitation is unlikely at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers would most likely exploit this via a CSRF vector, requiring a victim to be authenticated and to visit a site that submits a forged request to the vulnerable plugin.
OpenCVE Enrichment
EUVD