Impact
A CSRF vulnerability in the Simple Trackback Disabler plugin allows an attacker to cause a logged‑in user to execute actions that the plugin can perform, such as disabling trackbacks, without the user’s consent. This weakness is a well‑known injection of unauthorized request handling, identified as CWE‑352, and leads to potential misuse of site functionality and exposure to further attacks that rely on the user’s authenticated session.
Affected Systems
WordPress sites that have the misteraon Simple Trackback Disabler plugin installed at version 1.4 or earlier are affected. No newer versions are listed as vulnerable, and no explicit version range beyond 1.4 is defined.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while the EPSS score of less than 1% suggests low probability of exploitation at present. The vulnerability is not currently listed in the CISA KEV catalog. Attackers would typically exploit this through a crafted request that an authenticated user inadvertently submits, taking advantage of the plugin’s lack of CSRF protection. The required attacker skill is low, and the impact is limited to the actions the plugin performs but could disrupt site operations.
OpenCVE Enrichment
EUVD