Impact
A Cross‑Site Request Forgery vulnerability exists in Blend Media WordPress CTA easy‑sticky‑sidebar, allowing an attacker to submit forged state‑changing requests from an authenticated user’s browser. The flaw can lead to unauthorized modification of plugin settings or other site content, potentially altering the user experience or introducing malicious content. The weakness is classified as CWE‑352, indicating improper token verification during request handling.
Affected Systems
The vulnerability affects the WordPress CTA plugin from Blend Media for WordPress sites running any version through 1.7.0. The plugin is installed via WordPress, so all sites that have not yet upgraded beyond 1.7.0 are impacted.
Risk and Exploitability
The CVSS score of 4.3 depicts a medium severity risk. The EPSS score of <1% suggests that, at present, the probability of exploitation is very low. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. Based on the description, it is inferred that an attacker would need to persuade a legitimate user to visit a malicious page containing a forged request, thus relying on user interaction for the attack vector.
OpenCVE Enrichment
EUVD