Impact
The vulnerability is a CSRF flaw that lets an attacker submit forged requests from a victim's browser, enabling unauthorized execution of actions the victim is otherwise authorized to perform. The weakness is listed as CWE‑352.
Affected Systems
Any installation of WP Tools plugin version 5.24 or earlier is affected; this includes every release from the earliest available version up to 5.24. The plug‑in is provided by the vendor sminozzi, and no later version was known at the time of disclosure.
Risk and Exploitability
The CVSS base score of 4.3 indicates moderate severity, while the EPSS score of less than 1% shows a low probability of exploitation today. The vulnerability is not currently in the CISA KEV catalog. Based on the description, it is inferred that exploitation would require a victim who is already authenticated to the WordPress site and would rely on a malicious link or form presented to that user, so the attack is limited to the user’s privileges.
OpenCVE Enrichment
EUVD