Impact
This CVE documents a Cross‑Site Request Forgery vulnerability in straightvisions GmbH's SV Proven Expert plugin for WordPress. The flaw arises because the plugin does not enforce CSRF protection on requests that can alter its state, allowing a malicious site to submit forged requests that the plugin accepts. The impact is that any state‑changing request an authenticated user could normally perform through the plugin could be executed without the user’s knowledge.
Affected Systems
Straightvisions GmbH’s SV Proven Expert plugin distributed for WordPress. All released versions up to and including 2.0.06 are impacted, so any WordPress site that installs or has retained these versions is potentially susceptible.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity and an EPSS score of less than 1 % implies a very low current exploitation likelihood. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the likely attack vector involves an authenticated user loading a malicious page that submits a forged request; successful exploitation would allow the attacker to perform a state‑changing request with the privileges of the victim user.
OpenCVE Enrichment
EUVD