Impact
A CSRF flaw in the Infigo Software IS‑theme‑companion plugin permits an attacker to inject an object by forging a request to the plugin’s input handling. This weakness could lead to unauthorized manipulation of the plugin’s state or execution of unintended actions, compromising the integrity and confidentiality of the WordPress site.
Affected Systems
Infigo Software’s IS‑theme‑companion WordPress plugin, versions n/a through 1.59.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity, while the EPSS score of less than 1 % shows a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The typical attack path involves a maliciously crafted request sent from an authenticated user or from an external source that can force the user’s browser to submit the forged request, exploiting the missing CSRF protection.
OpenCVE Enrichment
EUVD