Impact
The SwiftNinjaPro Developer Tools Blocker plugin contains a CSRF flaw that lets a malicious actor force an authenticated user to execute unintended administrative actions on a WordPress site. By sending a crafted request, an attacker can modify settings, delete content, or perform any operation that the logged‑in user is allowed. This security weakness compromises the integrity of the site and can lead to full compromise if the affected account has elevated privileges.
Affected Systems
All installations of the SwiftNinjaPro Developer Tools Blocker plugin up to and including version 3.2.1 are vulnerable. No other versions are known to be affected based on the current CNA information.
Risk and Exploitability
The vulnerability has a CVSS score of 5.4, indicating moderate severity, and an EPSS score of less than 1%, showing a low likelihood of exploitation at present. It is not listed in the CISA KEV catalog. The attack vector is Web; an attacker only needs to rely on a victim who is already logged into WordPress with the plugin installed, and the exploit can be performed through a simple HTTP request without the need for additional privileges.
OpenCVE Enrichment
EUVD