Impact
The vulnerability is a Cross‑Site Request Forgery flaw that allows an attacker to perform state‑changing actions on a WordPress site using the flexo-social-gallery plugin without the user’s knowledge. Because the plugin fails to validate request authenticity, an attacker could invoke protected operations such as modifying gallery settings, uploading content, or altering configuration, potentially leading to data tampering or compromise of site integrity. The weakness is classified as CWE‑352.
Affected Systems
WordPress sites running the flexo-social-gallery plugin version 1.0006 or earlier, provided by flexostudio. No other vendors or product versions are affected.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity impact. The EPSS score of less than 1% suggests a very low likelihood of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to lure an authenticated user or coerce them to visit a crafted URL or submit a form that triggers the vulnerable request. No additional prerequisites beyond web access are required.
OpenCVE Enrichment
EUVD