Impact
The vulnerability is a classic Cross‑Site Request Forgery flaw that allows an attacker to trick a logged‑in user into executing unwanted actions through the WooCommerce Social Login plugin. This could enable the attacker to perform any operation that the logged‑in user is authorized to perform, such as initiating logins or changing account settings. The weakness corresponds to the common CSRF flaw identified as CWE‑352.
Affected Systems
All WordPress sites that use the wpweb WooCommerce Social Login plugin version 2.8.2 and earlier are affected. The plugin is part of the wpwebelite bundle and is typically installed as a standard WordPress plugin. No other products or versions are affected according to the CNA data.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is embedding crafted requests in malicious web pages or phishing emails; the attacker requires a victim who is logged into the target site. No additional network conditions are required beyond a browser-based interaction.
OpenCVE Enrichment
EUVD