Impact
This vulnerability is a cross‑site request forgery flaw (CWE‑352) in the Compact Admin WordPress plugin that allows a malicious site to coerce an authenticated user into submitting unintended requests to the plugin, thereby enabling execution of plugin actions under the victim’s credentials without the user’s knowledge.
Affected Systems
The Compact Admin WordPress plugin from reimund in all versions up to and including 1.3.3 is affected. No later versions were listed, so any installation using 1.3.3 or earlier is vulnerable.
Risk and Exploitability
The CVSS score of 4.3 suggests moderate severity, while the EPSS score of less than 1% indicates a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, and the primary attack vector is inferred to be a CSRF request forged from an external site, requiring the victim to be authenticated to the target site.
OpenCVE Enrichment
EUVD