Impact
The WP Post Hide plugin for WordPress contains a Cross‑Site Request Forgery flaw (CWE‑352) that permits attackers to force an authenticated user to perform unintended actions, such as changing post visibility or editing hidden content. This weakness allows malicious actors to manipulate content without the user's explicit consent, potentially compromising the integrity of the site’s content management.
Affected Systems
Xfinitysoft WP Post Hide plugin versions 1.0.9 and earlier are impacted; all earlier unspecified versions are also affected. Systems running these plugin versions on WordPress should be considered vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 4.3 and an EPSS score of less than 1%, indicating a low to moderate severity and a very low probability of exploitation. It is not listed in CISA’s KEV catalog. The likely attack vector is a crafted link or form that an authenticated user is tricked into visiting, causing the browser to send a privileged request that alters post settings.
OpenCVE Enrichment
EUVD