Impact
The WP Supersized plugin contains a CSRF flaw that enables an attacker to submit unauthorized state‑changing requests on behalf of an authenticated WordPress user. The vulnerability is identified as CWE‑352 and could allow malicious actors to alter plugin settings, publish content, or perform other sensitive actions without the user's knowledge.
Affected Systems
WordPress sites that have the Benoit De Boeck WP Supersized plugin installed in any version up to and including 3.1.6 are affected. All WordPress installations hosting this plugin prior to a newer release are potentially vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact, while the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to coerce a logged‑in user into visiting a malicious webpage that triggers the CSRF request, which is the typical attack vector for this class of flaw; this is inferred from the nature of CSRF and not directly stated in the advisory.
OpenCVE Enrichment
EUVD