Impact
The plugin contains a Cross‑Site Request Forgery (CSRF) vulnerability that allows an attacker to perform actions on the site without the victim’s consent, enabling unauthorized operations such as content modification or settings changes. The flaw is categorized as CWE‑352.
Affected Systems
NIX Anti‑Spam Light developed by NIX Solutions Ltd is affected for all versions up to and including 0.0.4; no lower bound is specified. The plugin is a WordPress add‑on.
Risk and Exploitability
The CVSS score of 7.1 indicates a high potential severity, but the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not listed in CISA KEV. A typical attack would rely on tricking an authenticated user into visiting a crafted link or email, thereby sending inadvertent requests that perform privileged actions. The flaw requires the victim’s session and active interaction, so the risk is moderate but rises if CSRF defenses are inadequate.
OpenCVE Enrichment
EUVD