Impact
A cross‑site request forgery flaw allows an attacker to manipulate the settings page of the WP Mapa Politico España plugin, potentially altering site behavior or configuration without proper authorization. The weakness is classified as CWE‑352. Since the vulnerability permits changes to plugin configuration, it can disrupt site functionality or compromise data integrity.
Affected Systems
The issue affects WordPress sites that have the WP Mapa Politico España plugin up to and including version 3.8.0, released by Juan Carlos. Any installation of the plugin in this version range is vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity; the EPSS score of below 1 % suggests exploitation is unlikely in the short term, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the most likely attack vector requires a victim user who is authenticated and has permission to access the plugin settings; a malicious site can craft a link that triggers an undesired change when the user visits it.
OpenCVE Enrichment
EUVD