Impact
The vulnerability permits an attacker to forge state‑changing requests to the SEO Backlink Monitor plugin for WordPress. Because CSRF protection is missing, a malicious site could force a logged‑in administrator to execute privileged operations such as altering backlink data or invoking other plugin functions. This constitutes an integrity or confidentiality compromise depending on the specific action taken by the attacker. The vendor description only confirms the presence of CSRF and does not enumerate the affected operations.
Affected Systems
The flaw affects any installation of activewebsight SEO Backlink Monitor for WordPress up through version 1.8.0. Users of 1.8.0 or earlier, regardless of the WordPress core version or other plugins, are potentially vulnerable. No higher versions are indicated as affected by the CVE data.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, while the EPSS score of less than 1% signals a very low probability of exploitation in the wild. This vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a crafted external request that an authenticated administrator is tricked into executing; the exact mechanics are inferred because the vendor description does not detail the required conditions.
OpenCVE Enrichment
EUVD