Impact
The WP Church Donation plugin for WordPress does not implement Anti‑Cross‑Site Request Forgery protection for its endpoints. Because of this, if a logged‑in user visits a crafted URL, the plugin may process a request that performs a state‑changing action on the user’s behalf. The exact operation that can be triggered depends on the functions exposed by the plugin and the user’s role. This weakness is classified as CWE‑352.
Affected Systems
WordPress sites that have installed the Ashish Ajani WP Church Donation plugin version 1.7 or earlier are affected. Any authenticated user who can access donation‑related functions within WordPress is at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate overall risk, while the EPSS score of less than 1% shows a low probability of exploitation in the current landscape, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack scenario involves an attacker compelling a legitimate user to visit a malicious page that submits a request to the plugin. This inference is drawn because the vulnerability description only states that a CSRF flaw exists; it does not detail the exact exploitation technique.
OpenCVE Enrichment
EUVD