Impact
This flaw is a Cross‑Site Request Forgery vulnerability in the WP Table Builder WordPress plugin up to version 2.0.6. An attacker can cause an authenticated user to perform actions that the user is allowed to execute, without the attacker having direct access to the user’s credentials. The description does not enumerate specific actions beyond the general ability to perform unintended requests.
Affected Systems
WP Table Builder plugin for WordPress, any installation using version 2.0.6 or earlier. The issue arises from insufficient protection against forged requests and can affect all sites that have the plugin installed in the affected versions.
Risk and Exploitability
The CVSS score of 4.3 indicates a low to moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation at this time, and the vulnerability is not listed in CISA KEV, so no confirmed public attacks exist. The likely attack vector is a malicious website that loads the target site while an authenticated user is active; based on the description it is inferred that the attacker does not need to bypass authentication, but must trick the victim into issuing the forged request.
OpenCVE Enrichment
EUVD