Impact
A CSRF flaw exists in the Elfsight Testimonials Slider plugin up to version 1.0.1 that permits an attacker to alter plugin settings without the authenticated user’s consent. The weakness is classified as CWE‑352 and can change how testimonials are displayed or otherwise configure the plugin.
Affected Systems
The vulnerability affects all releases of the Elfsight Testimonials Slider plugin from its initial deployment through version 1.0.1. Any WordPress site running this plugin at or below that version is potentially impacted.
Risk and Exploitability
The CVSS score of 5.4 places the flaw in the moderate range, while the EPSS score of less than 1 % indicates that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. The attack would likely rely on an attacker convincing a logged‑in user—typically one with administrative or content‑management rights—to visit a malicious link that submits a forged POST request to the plugin’s settings endpoint. The attacker does not need to know the user’s credentials; the exploit depends on the browser automatically sending the user’s session token with the request.
OpenCVE Enrichment
EUVD