Impact
The Hesabfa Accounting plugin for WordPress contains a Cross‑Site Request Forgery vulnerability that would allow an attacker to trick an authenticated user into submitting requests that the plugin accepts and processes with the user’s privileges. Based on the description, it is inferred that such forged requests could lead to unauthorized execution of privileged actions within the accounting functions of the site.
Affected Systems
The vulnerability affects the Hesabfa Accounting plugin distributed by Saeed Sattar Beglou. Any WordPress installation using version 2.2.5 or earlier is susceptible.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity, while an EPSS score of <1% suggests the likelihood of exploitation is very low. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the target user to be logged into the WordPress site and visit a malicious or compromised page that triggers the forged request, thereby leveraging the victim’s authenticated session.
OpenCVE Enrichment
EUVD