Impact
The Seven Stars WordPress theme contains a CSRF flaw that fails to validate request tokens. While the CVE description does not enumerate the actions that can be performed, such a flaw could allow an attacker to trigger unintended state‑changing actions through a crafted request. The potential for data modification or content publishing exists, but the exact impact is uncertain based on the information supplied.
Affected Systems
All installations of the WordPress theme Seven Stars by themeton with version 1.4.4 or earlier are affected. No newer versions are known to be impacted.
Risk and Exploitability
The CVSS score of 4.3 denotes a moderate severity, and the EPSS score of < 1% suggests a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, indicating no publicly reported exploits. The likely attack vector involves an authenticated user being tricked into visiting a malicious page that submits a request lacking proper CSRF protection, but this scenario is inferred from the nature of CSRF vulnerabilities rather than stated in the CVE.
OpenCVE Enrichment
EUVD