Impact
Astoundify Listify theme versions up to 3.2.5 contain a Cross‑Site Request Forgery flaw classified as CWE‑352. The vulnerability permits an attacker to create a forged request that the theme will process, potentially enabling unauthorized actions against the website. The description does not specify whether authentication is required for the affected operation, so the scope of impact for unauthenticated versus authenticated users remains unclear.
Affected Systems
WordPress sites that deploy Astoundify Listify theme, including all releases up through version 3.2.5, are affected. No other WordPress themes or plugins are listed in this CVE.
Risk and Exploitability
The CVSS score of 4.3 places the issue in the medium severity range, while the EPSS score of less than 1% indicates a very low exploitation probability in the near term. The vulnerability is not in the CISA KEV catalog. Based on typical CSRF exploitation patterns, the attacker would need to entice an authenticated user to visit a malicious or compromised site to have the forged request processed. The low EPSS suggests limited active exploitation, but organizations should still remediate by applying an available fix or strengthening CSRF defenses.
OpenCVE Enrichment