Impact
Cross‑Site Request Forgery (CSRF) is a vulnerability that enables an attacker to compel an authenticated user to perform actions within the Anthologize WordPress plugin without that user’s consent. The flaw can result in unauthorized changes to posts, settings or other content managed by the plugin, thereby compromising the integrity of the site’s information.
Affected Systems
The vulnerability is present in the Boone Gorges Anthologize WordPress plugin versions 0.8.3 and earlier. Any WordPress site that has this plugin installed and is running a version at or below 0.8.3 is exposed.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate level of risk, while the EPSS score of less than 1% suggests a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a client‑side CSRF request, requiring an attacker to lure a logged‑in user to trigger an undesired action; this exploitation path does not demand advanced skills but relies on user interaction and an authenticated session.
OpenCVE Enrichment
EUVD