Impact
The Ever Accounting plugin for WordPress contains a Cross‑Site Request Forgery flaw that allows an attacker to make a logged‑in user execute unintended actions without the user's consent. The vulnerability is defined as CWE‑352, a weakness in application input handling. If exploited, the attacker could perform any operation that the authenticated user is allowed to do, affecting confidentiality, integrity and availability of the affected system.
Affected Systems
The Ever Accounting plugin for WordPress versions up to and including 2.1.5. There is no narrower version range specified.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% shows that the probability of exploitation is low at the time of this analysis. The vulnerability is not listed in CISA’s KEV catalog. Based on the nature of CSRF, the likely attack vector requires an authenticated user to visit a crafted URL, implying that the attacker must first lure or entice a legitimate user to trigger the request. No other environmental prerequisites are detailed in the description.
OpenCVE Enrichment
EUVD