Impact
The vulnerability is a Cross‑Site Request Forgery flaw in the WordPress DesignO plugin through version 2.6.0. An attacker can cause a logged‑in user to submit a forged request that the plugin accepts as legitimate, enabling the plugin to perform privileged actions without the user’s knowledge. The weakness is classified as CWE‑352 and represents a request‑forgery problem.
Affected Systems
The DesignO plugin from the earliest available release up to and including version 2.6.0 is affected. Site owners who are running any of these versions are at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1 % signals a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to trick an authenticated user into sending a forged request; no public exploit code has been disclosed to date.
OpenCVE Enrichment
EUVD