Impact
A Cross‑Site Request Forgery flaw exists in the Theme Changer plugin that permits an attacker to submit crafted requests from a victim’s browser while the victim is authenticated with WordPress. The vulnerability can be used to change the active theme or modify theme settings without permission, potentially defacing the site, injecting malicious code, or facilitating further attacks on the hooked site. It is a classic CSRF weakness (CWE‑352).
Affected Systems
WordPress sites running the momen2009 Theme Changer plugin version 1.4 or earlier. Users should verify that the plugin is in this version range or earlier, as the issue is not present in later releases.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% signals a low likelihood of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attack likely requires an authenticated user to visit a malicious link that triggers a state‑changing request against the site. No additional conditions are noted beyond the typical CSRF prerequisites.
OpenCVE Enrichment
EUVD