Impact
The vulnerability is a Cross‑Site Request Forgery (CSRF) flaw in the DAEXT Soccer Live Scores WordPress plugin. It allows an attacker to cause the plugin to execute actions on behalf of an authenticated user by forging requests, potentially compromising data integrity or performing unauthorized operations. The weakness is catalogued as CWE‑352.
Affected Systems
The issue affects the Soccer Live Scores plugin from the earliest version through 1.0.5. It impacts WordPress sites that have this plugin installed in any of those versions, requiring specific attention for users of version 1.0.5 or older.
Risk and Exploitability
Based on the description, it is inferred that the attacker would need to send forged HTTP requests while a site visitor is logged in, exploiting the plugin’s lack of CSRF protection. With a CVSS score of 4.3 the risk is moderate, and the EPSS score of less than 1 % suggests a low exploitation probability at present. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment
EUVD