Impact
This CSRF flaw allows an attacker to cause authenticated users of a WordPress site that has the affected plugin installed to unknowingly submit requests that perform unwanted actions, potentially exposing sensitive data or creating unauthorized entries.
Affected Systems
The flaw affects the Codebangers All in One Time Clock Lite plugin for WordPress. All versions from the earliest available through any version prior to 1.3.326 are vulnerable; users must update to 1.3.326 or later.
Risk and Exploitability
The CVSS score is 4.3 and the EPSS score is reported as less than 1%, indicating a low overall severity and a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, further reducing the perceived threat level. The likely attack vector is a malicious web page that induces an authenticated user to visit a crafted URL or forms that trigger the unprotected plugin endpoints, exploiting the missing CSRF protection.
OpenCVE Enrichment
EUVD