Impact
A Cross‑Site Request Forgery vulnerability exists in the Slickstream slick‑engagement WordPress plugin. The flaw allows an attacker to construct a malicious request that a logged‑in user will unknowingly submit, potentially performing privileged actions on the website. This weakness does not grant code execution or remote access, but may lead to account takeover or data manipulation, classified as a type 1 input validation flaw (CWE‑352).
Affected Systems
The vulnerability affects the Slickstream slick‑engagement plugin for WordPress, impacting all installations up to and including version 2.0.3. If customers are using any of these versions, they are exposed to the CSRF flaw.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact if exploited. The EPSS score is less than 1%, showing that the probability of exploitation is very low, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog. Based on the description, the likely attack vector is a web page that coerces an authenticated user into submitting a forged request; no elevated privileges are required beyond a logged‑in session.
OpenCVE Enrichment
EUVD