Impact
The vulnerability is a CSRF flaw affecting the Apimo Connector plugin for WordPress. It allows attackers who can trick a logged‑in user into visiting a crafted URL to cause the server to change plugin settings without the user's consent. This weakness is categorized as CWE‑352 and can lead to unauthorized changes affecting site configuration and potentially site functionality.
Affected Systems
The issue is present in all versions of the Apimo Connector up to and including 2.6.5.1 deployed by the Proptech Plugin vendor. No specific sub‑version range beyond the latest publicly available is listed, so any installation of 2.6.5.1 or older is considered vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score is below 1%, suggesting a low probability of exploitation at present, and the vulnerability is not part of the CISA KEV catalog. Likely exploited through a web request originating from a victim’s browser session; an attacker would need to lure the victim to a malicious link or form that triggers the setting change request. While it does not grant remote code execution, the ability to alter settings can undermine site integrity and trust.
OpenCVE Enrichment
EUVD