Impact
The vulnerability is a CSRF flaw in the Flexible FAQ plugin that can be exploited when a logged‑in user visits a crafted link. The attacker can make the site perform unintended changes such as adding, editing, or deleting FAQ items, thereby manipulating the information displayed to other visitors. This is a classic instance of CWE‑352, where the attacker forces the victim to submit a request they did not authorize.
Affected Systems
All installations of the WordPress Flexible FAQ plugin developed by Bage, version 0.2 and earlier, are vulnerable. The issue applies from the earliest available release through 0.2, so any site running a version not newer than 0.2 is susceptible.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of widespread exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an authenticated user who is logged into the WordPress admin or front‑end area; an attacker simply needs to trick that user into visiting a malicious URL, which is a typical CSRF attack vector.
OpenCVE Enrichment
EUVD