Impact
This vulnerability is a Cross‑Site Request Forgery flaw in the CloudRedux Product Notices for WooCommerce plugin that allows an attacker to coerce an authenticated user into performing unwanted actions. Because the plugin lacks proper nonce or user‑validation checks, as inferred from the CVE description, a malicious link or form can trigger state‑changing operations without the user’s consent, potentially leading to unauthorized content modifications or other integrity problems for the site.
Affected Systems
WordPress sites running CloudRedux Product Notices for WooCommerce plugin version 1.3.4 or earlier are affected. The flaw applies to all installations using any priority setting up through the specified version range.
Risk and Exploitability
The CVSS score of 4.3 reflects moderate severity, while the EPSS score listed as <1% indicates a low likelihood of exploitation in the wild. The vulnerability is not included in the CISA KEV catalog. Attackers can likely exploit this flaw by delivering a crafted link or form to an authenticated administrator, as inferred from the CVE description; if activated, the plugin will perform the requested state‑changing operation with the privileges of the targeted user, potentially allowing modification or deletion of product notices or other privileged actions.
OpenCVE Enrichment
EUVD