Impact
A Cross‑Site Request Forgery flaw in the WordPress plugin "Popup for CF7 with Sweet Alert" enables an attacker to force a logged‑in user to submit plugin requests without the user’s consent, as the plugin lacks an anti‑CSRF token. The weakness is identified as CWE‑352 and permits the execution of unintended actions within the plugin’s context. The impact is limited to the plugin’s capabilities and does not directly affect the underlying WordPress installation.
Affected Systems
All sites running the plugin from the earliest release through version 1.6.5, distributed by Metin Saraç, are affected. The vulnerability applies to any WordPress installation that includes one of these versions.
Risk and Exploitability
The CVSS score of 4.3 signifies low‑to‑moderate severity. The EPSS score of < 1 % indicates a very low probability of exploitation in the current landscape, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to possess a session belonging to a legitimate user; this is inferred from the CSRF nature of the flaw.
OpenCVE Enrichment
EUVD