Impact
The vulnerability is a Cross‑Site Request Forgery (CSRF) issue affecting the ValidateCertify plugin for WordPress. It permits an attacker to manipulate certificate related data by inducing a logged‑in administrator or user to send a forged request to the plugin’s endpoints. Based on typical CSRF behavior, it is inferred that an attacker could cause unintended actions such as approving or tampering with course certificates.
Affected Systems
WordPress installations that have any release of the Javier Revilla ValidateCertify plugin up to and including version 1.6.4 are affected.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk while the EPSS score of less than 1 % shows a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is a CSRF that requires a victim to be authenticated on the target site and to unknowingly trigger a request to the plugin’s endpoint. Because the flaw does not provide code execution or system‑wide access, the damage is limited to the plugin‑related data. Nonetheless, the moderate severity and potential for data tampering warrant timely remediation.
OpenCVE Enrichment
EUVD