Impact
The vulnerability is a CSRF flaw in the WordPress Woocommerce Role Pricing plugin that allows a forged request to be sent to the plugin’s endpoints without proper verification. Because the plugin does not enforce origin or nonce checks, an attacker can submit state‑changing requests that lead to undesired changes in the plugin configuration. The flaw is identified as CWE‑352.
Affected Systems
All installations of the ablancodev Woocommerce Role Pricing plugin from its earliest release through and including version 3.5.6 are affected. Any WordPress site running the plugin in these versions is potentially vulnerable.
Risk and Exploitability
The CVSS base score of 4.3 places this vulnerability in the medium severity range, while the EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves a malicious web page that forces a logged‑in user’s browser to send a request to the plugin’s admin‑ajax endpoint without a proper CSRF token. Once the user is authenticated, the exploit is straightforward.
OpenCVE Enrichment
EUVD