Impact
The Freetobook Responsive Widget plugin for WordPress contains a Cross‑Site Request Forgery vulnerability (CWE‑352). An attacker can trick an authenticated user into unknowingly sending a request that the plugin processes, potentially allowing the attacker to modify widget settings or perform actions within the plugin on behalf of the user.
Affected Systems
The vulnerability affects the Freetobook Responsive Widget plugin for WordPress, versions 1.1 and earlier.
Risk and Exploitability
The CVSS score for this flaw is 4.3, indicating a moderate risk. The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a low likelihood of widespread exploitation. The typical attack vector requires a victim to be logged into a WordPress site where the plugin is installed; the attacker deceives the user into visiting a crafted page that sends a forged request to the site. No additional conditions beyond user authentication appear to be required to exploit the weakness.
OpenCVE Enrichment
EUVD