Impact
The vulnerability is a Cross‑Site Request Forgery flaw in the WordPress TrustMate.io – WooCommerce integration plugin. It permits an attacker to cause a legitimate user to issue requests that the plugin will process, without the user’s consent. The weakness is identified as CWE‑352.
Affected Systems
The ThreatMate.io – WooCommerce integration plugin, maintained by michalzagdan, is affected for all releases up to and including version 1.16.0. Any WordPress site hosting these versions is vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity and the EPSS score of less than 1% suggests a very low probability of exploitation at the time of this assessment. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated user unknowingly visiting a malicious site that submits forged requests to the plugin’s endpoints; the attacker relies on the user’s legitimate authentication to carry out the action.
OpenCVE Enrichment
EUVD