Impact
A CSRF vulnerability exists in the Printeers Print & Ship plugin that permits an attacker to perform actions on behalf of a logged‑in user without their knowledge. The flaw allows the execution of privileged operations that the plugin provides, potentially leading to unauthorized changes or data exposure. The weakness is classified as a typical CSRF flaw (CWE‑352).
Affected Systems
The vulnerability affects the Printeers Print & Ship WordPress plugin for all released versions up to and including 1.17.0. Any site installing the plugin at any of these versions is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. EPSS indicates a very low exploitation probability (<1%), and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is that an attacker tricks an authenticated user into visiting a crafted URL or link, resulting in the plugin executing unwanted requests under that user's credentials. No special conditions beyond user authentication and a crafted request are required.
OpenCVE Enrichment
EUVD