Impact
This vulnerability enables an attacker to perform Cross‑Site Request Forgery against the Year Make Model Search for WooCommerce plugin and change its configuration without proper authorization. By forging an authenticated request, the attacker can modify settings or disable security features, potentially disrupting the store’s operation or facilitating further attacks.
Affected Systems
All installations of the Pektsekye Year Make Model Search for WooCommerce plugin with a version of 1.0.11 or earlier are affected. No specific patch version is listed; the vulnerability applies to the entire ≤1.0.11 range.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score of less than 1% suggests that the exploitation likelihood is currently low, and the vulnerability is not listed in CISA’s KEV catalog, implying no known active exploitation at the time. The attack vector is inferred to be a user‑initiated CSRF request that requires the victim to be authenticated, as the description only states that the flaw permits CSRF to change settings.
OpenCVE Enrichment
EUVD