Impact
The BCM Duplicate Menu plugin for WordPress includes a Cross‑Site Request Forgery vulnerability that allows an attacker to send forged requests on behalf of an authenticated user. The weakness is classified as CWE‑352 and is not a code execution flaw; it simply enables the attacker to trigger plugin actions that the victim is already authorized to perform. As a result, unauthorized changes within the site can be made without the user’s knowledge.
Affected Systems
The vulnerability affects the Bjorn Manintveld BCM Duplicate Menu WordPress plugin up through version 1.1.3. Any installation using a version 1.1.3 or earlier is at risk.
Risk and Exploitability
The CVSS score of 4.3 reflects a moderate risk given that the attacker must trick a victim into visiting a crafted URL or submitting a malicious form. The EPSS score of less than 1% indicates that spontaneous exploitation is unlikely at present, and the issue is not listed in CISA's KEV catalog. Nevertheless, because the flaw relies on a CSRF vector, an attacker can automate the attack once a target user is authenticated, making it a concern for sites with many privileged users.
OpenCVE Enrichment
EUVD