Impact
The vulnerability is a cross‑site request forgery flaw in the WordPress Fluent Support plugin, version 1.9.1 or earlier. The plugin does not verify that incoming requests are authorized, allowing an attacker to send a request that the plugin will process as if it came from a legitimate user. This flaw exists because the plugin lacks proper CSRF protections.
Affected Systems
Any WordPress installation that has the Shahjahan Jewel Fluent Support plugin installed at version 1.9.1 or older is affected. Sites that provide logged‑in users with privileges sufficient to exercise the plugin’s functionality are at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low current likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. CSRF attacks can be performed by sending a crafted link or form to any authenticated user, so the risk depends on the plugin’s level of access and whether the attacker can convince a user to visit a malicious URL.
OpenCVE Enrichment
EUVD