Impact
This vulnerability allows an attacker to perform a cross‑site request forgery against users of the Saiful Islam UltraAddons Elementor Lite plugin. By exploiting a missing verification token, an attacker can trick a logged‑in administrator into unknowingly carrying out actions the attacker desires. The impact is the loss of data integrity and potential unauthorized configuration changes or content modification.
Affected Systems
The Saiful Islam UltraAddons Elementor Lite plugin for WordPress is affected in all releases up to and including 2.0.2. Sites using any older or intermediate versions of the plugin are therefore vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score is below 1%, suggesting a low likelihood of exploitation in the near term, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the attack requires only a CSRF vector and can be carried out by anyone who can trick an authenticated administrator into visiting a crafted URL or submitting a malicious form.
OpenCVE Enrichment
EUVD