Impact
The Rollbar WordPress plugin versions up to 2.7.1 contains a CSRF flaw that allows an attacker to perform unauthorized actions on behalf of an authenticated user within that site. This vulnerability stems from insufficient validation of the request source, a typical instance of CWE‑352. An attacker can trick a logged‑in user into sending a malicious request, which the plugin will accept and execute, potentially exposing or modifying sensitive site data.
Affected Systems
The affected product is the WordPress Rollbar plugin from rollbar:Rollbar. All releases from the earliest available version through version 2.7.1 are vulnerable. Any WordPress site that has not yet upgraded beyond 2.7.1 and still uses this plugin is at risk.
Risk and Exploitability
The CVSS score is 5.4, indicating a medium impact if exploited. The EPSS score is less than 1%, implying a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack path is inferred to be straightforward: an attacker crafts a request to a target site where a user is logged in, and performs a state‑changing operation via the plugin. This can lead to unauthorized changes, data leakage, or other unintended side effects.
OpenCVE Enrichment
EUVD