Impact
The Helmut Wandl Advanced Settings plugin contains a CSRF flaw that allows an attacker to trick a logged‑in user into submitting privileged requests. Because the plugin does not verify a proper CSRF token, an unauthenticated attacker can craft a link or form that, when visited by an administrator, executes actions such as changing settings, uploading files, or other administrative tasks. This can lead to privilege escalation or further compromise of the WordPress site.
Affected Systems
The vulnerability affects all installations of the Advanced Settings plugin version 3.0.1 or earlier. Users running any of those versions on a WordPress site are impacted.
Risk and Exploitability
This flaw carries a CVSS score of 4.3 (medium) and an EPSS score of less than 1 %, indicating a low likelihood of exploitation under current conditions. It is not listed in the CISA KEV catalog. Attackers would need a victim who is logged into WordPress and to send them a malicious link or embed the attack in a page they visit. The vulnerability does not enable direct code execution; mitigation relies primarily on patching or disabling the plugin.
OpenCVE Enrichment
EUVD