Impact
A vulnerability in the Matthias Nordwig plugin allows attackers to perform Cross‑Site Request Forgery (CSRF). The flaw enables the forging of requests that appear to originate from an authenticated WordPress user, but specific consequences are not detailed in the advisory. The weakness is classified as CWE‑352.
Affected Systems
WordPress users running the Anti‑spam, Spam protection, ReCaptcha for all forms and GDPR‑compliant plugin by Matthias Nordwig, any version up to and including 4.1.1, are affected.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1 % implies a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a malicious link or third‑party page that coerces a logged‑in user into submitting a forged request.
OpenCVE Enrichment
EUVD