Impact
A Cross-Site Request Forgery (CSRF) flaw exists in IT Path Solutions SCSS WP Editor plugin versions 1.2.1 and older, permitting an attacker to prompt an authenticated user to perform unintended actions on the WordPress site. This weakness can lead to unauthorized changes or actions carried out through the victim’s session, potentially compromising site integrity.
Affected Systems
The vulnerability affects the SCSS WP Editor plugin from IT Path Solutions. Any installation of the plugin version 1.2.1 or earlier is impacted, regardless of the WordPress core version.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate potential for damage, while the EPSS score of less than 1% suggests a very low probability of immediate exploitation. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires an attacker to induce a logged‑in administrator or other privileged user to visit a malicious URL or otherwise trigger the forged request.
OpenCVE Enrichment
EUVD