Impact
A CSRF flaw in the senols GPT3 AI Content Writer plugin allows an attacker to craft a request that forces a logged‑in user to trigger the prompt generation function without their knowledge. The resulting prompt is executed by the plugin, potentially generating content or code on behalf of the victim. The weakness is documented as CWE‑352.
Affected Systems
WordPress sites running senols GPT3 AI Content Writer through version 1.9.14 are affected; earlier releases are not vulnerable. Operators should check the installed plugin version and ensure it is above 1.9.14 to avoid the flaw.
Risk and Exploitability
The CVSS score of 4.3 indicates medium severity, and the EPSS score of < 1 % shows the likelihood of exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to require the victim to be logged in and to be tricked into visiting a malicious page, after which the attacker can trigger the prompt‑generation endpoint. Success would lead to unauthorized use of the plugin’s prompt generator but does not provide direct code execution or broader system compromise.
OpenCVE Enrichment
EUVD