Impact
This CVE identifies a Cross‑Site Request Forgery flaw in the rainafarai Notification for Telegram WordPress plugin. The vulnerability allows a malicious site to send forged requests on behalf of an authenticated user, potentially enabling the attacker to perform unauthorized actions within the plugin without the user’s consent.
Affected Systems
The flaw affects all releases of rainafarai’s Notification for Telegram plugin up to and including version 3.5 on any WordPress installation. Site owners using these versions are impacted unless the plugin has been removed or disabled.
Risk and Exploitability
The CVSS base score of 4.3 indicates moderate severity, and the EPSS score of less than 1% points to a low likelihood of exploitation in the field. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely exploit the flaw by tricking a logged‑in user into visiting a malicious page that submits CSRF requests to the vulnerable plugin endpoints.
OpenCVE Enrichment
EUVD