Impact
WordPress writesonic plugin versions through 1.0.5 contain a vulnerability that allows attackers to forge requests without authentication, enabling them to exploit actions authorized only for legitimate users. The weakness is a classic CSRF flaw (CWE‑352) that can lead to unauthorized content creation, configuration changes, or other privileged actions performed on behalf of the victim who visits a malicious site.
Affected Systems
The vulnerability affects the WriteSonic plugin for WordPress, specifically all releases from the first available version up to and including 1.0.5. Site administrators using any of these plugin versions are at risk until the issue is resolved.
Risk and Exploitability
The CVSS score of 5.4 indicates medium severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, which limits visibility to large‑scale attacks. However, because the flaw permits authenticated actions to be performed without user consent, it can be exploited via socially engineered links or embedded malicious content that a logged‑in user would unknowingly follow.
OpenCVE Enrichment
EUVD