Impact
The vulnerability is a CSRF flaw in the Virusdie WordPress plugin that allows attackers to perform actions on behalf of authenticated users. By crafting a malicious request that an authenticated site visitor unknowingly submits, an attacker might change settings, publish content, or otherwise compromise the site. The flaw arises from inadequate verification of a CSRF token, as identified by CWE-352.
Affected Systems
The Virusdie plugin for WordPress is affected. All versions from the first release up to and including 1.1.3 are vulnerable.
Risk and Exploitability
The CVSS score of 5.4 shows moderate severity. The EPSS score of less than 1% indicates a low likelihood of exploitation at present, and it is not listed in the CISA KEV catalog. The likely attack vector is a remote web request that a victim user submits while authenticated; the attacker would need to lure the user to a crafted link or embed the request in a trusted site. Successful exploitation would allow the attacker to carry out the intended action as the victim user without their knowledge.
OpenCVE Enrichment
EUVD