Impact
The vulnerability is a CSRF flaw in the Rustaurius Ultimate WP Mail plugin. This issue allows an attacker to cause authenticated users of a WordPress site to perform unintended actions by submitting malicious requests through the plugin. The flaw is identified as CWE‑352 and manifests when state‑changing operations are executed without proper user-initiated confirmation.
Affected Systems
The flaw affects the Ultimate WP Mail plugin from Rustaurius, specifically all releases up to and including version 1.3.4. Site administrators should verify if they are running a vulnerable version of the plugin and consider upgrading or disabling it.
Risk and Exploitability
The CVSS score of 5.4 places this vulnerability in the medium severity range, while an EPSS score of less than 1 % indicates a low probability of exploitation at the time of this analysis. The vulnerability is not listed in CISA’s KEV catalog. If exploited, an attacker could abuse the plugin to carry out actions that the victim’s authenticated session would normally allow, such as unintended form submissions or configuration changes. The most likely attack path is a web‑based CSRF exploit that relies on a victim user’s authenticated session and a maliciously crafted request.
OpenCVE Enrichment
EUVD