Impact
The CVE notes that the Trust Payments Gateway for WooCommerce (JavaScript Library) plugin allows Cross Site Request Forgery (CSRF). The flaw is a classic CSRF issue (CWE‑352) and does not ensure that incoming requests are properly authenticated, potentially permitting unintended actions to be performed on behalf of an authenticated user. Based on the description, the vulnerability could affect any state‑changing operation processed by the plugin.
Affected Systems
All installations of the Trust Payments Gateway for WooCommerce (JavaScript Library) plugin with version 1.3.6 or earlier are impacted. The plugin is provided by Trust Payments and is used within WordPress‑based WooCommerce sites, regardless of the specific WooCommerce version.
Risk and Exploitability
The CVSS v3.1 score of 4.3 places this issue in the Low severity range, while the EPSS score of less than 1% indicates a very low likelihood of exploitation at present. The vulnerability is not listed in CISA KEV, suggesting no widely used exploits are known. Common CSRF exploit scenarios would require a victim to be logged into the store and visit a malicious site that issues a forged request to the plugin; this inference follows typical CSRF attack patterns.
OpenCVE Enrichment
EUVD