Impact
A CSRF vulnerability in the Invelity MyGLS connect plugin for WordPress allows a remote attacker to forge authenticated requests and inject objects into the application. The flaw is classified as CWE‑352, which can lead to arbitrary state‑changing operations performed on behalf of a legitimate user, potentially compromising the integrity of the site.
Affected Systems
The issue affects the Invelity MyGLS connect plugin, any WordPress installation running version 1.1.1 or earlier. No other vendors are listed as impacted.
Risk and Exploitability
The vulnerability carries a high CVSS score of 8.8. Its EPSS score is below 1 %, indicating a low but non‑zero likelihood of exploitation in the wild, and it is not currently listed in the CISA KEV catalog. The attack vector is inferred to be a classic CSRF scenario where an attacker crafts a malicious page that initiates an authenticated request from a victim’s browser, exploiting the lack of adequate request validation within the plugin’s state‑changing endpoints.
OpenCVE Enrichment
EUVD