Impact
The Easy PayPal Events plugin, up to version 1.2.2, contains a CSRF flaw identified as CWE‑352. The vulnerability allows an attacker to forge a request from an authenticated user’s browser, potentially leading to unintended changes or data leakage on the WordPress site. It carries a CVSS score of 4.3, indicating moderate severity.
Affected Systems
Affected products are WordPress sites using the Scott Paterson Easy PayPal Events plugin in any release up through 1.2.2. Site administrators should confirm whether the installed plugin version falls within this range.
Risk and Exploitability
The EPSS score is below 1 %, signifying a low likelihood that the flaw will be widely exploited. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a user who is logged into the site and visits a malicious page that submits a forged request, but this is inferred because the description does not contain explicit attack details. Given the moderate CVSS score and low EPSS, the overall risk is moderate but not negligible for sites that employ the plugin.
OpenCVE Enrichment
EUVD