Impact
The vulnerability is a Cross‑Site Request Forgery flaw that allows an attacker to send forged requests to the OwnerRez API, potentially causing unintended actions to be performed on behalf of an authenticated user. The flaw does not directly disclose data but can lead to unauthorized changes or executions within the system. The weakness is identified as CWE‑352.
Affected Systems
The affected product is the OwnerRez API used by WordPress sites. Vulnerable releases are all versions up through and including 1.2.0.
Risk and Exploitability
The issue carries a CVSS score of 4.3, indicating a moderate impact. The EPSS score is below 1 %, suggesting a very low probability of exploitation at present. It is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers would likely rely on tricking a victim into visiting a malicious page while the victim is logged into the WordPress site, sending forged requests to the API endpoint.
OpenCVE Enrichment
EUVD