Impact
The WebAppick Challan plugin for WordPress includes a Cross‑Site Request Forgery flaw that allows an attacker to cause authenticated users to perform privileged actions without their consent, leading to privilege escalation within the WordPress site. The vulnerability enables the attacker to tamper with the plugin’s sensitive functionality, potentially creating or modifying resources that normally require elevated rights.
Affected Systems
All installations of the WebAppick Challan plugin for WordPress with a version through 3.7.58 are affected. No specific vendor version numbers are provided beyond the maximum known vulnerable release.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity level, but the EPSS score of less than 1% shows the current exploitation probability is very low. The vulnerability is not yet listed in the CISA KEV catalog. Attackers would need to trick a privileged user into visiting a malicious URL or submitting a crafted form that forces the browser to send a state‑changing request to the plugin. If successful, the malicious actor could gain elevated privileges through the plugin’s functionality.
OpenCVE Enrichment
EUVD