Impact
The Duplicate Content Cure plugin by Badi Jones has a CSRF flaw that lets an attacker forge authenticated requests against a WordPress site using older versions of the plug‑in. The weakness permits unintended state‑changing actions, exposing or corrupting content without the user’s consent, and is classified as CWE‑352.
Affected Systems
This vulnerability covers any installation of the Duplicate Content Cure plug‑in from its first release through version 1.0. Sites running the plugin in that range are in scope, as no later versions are listed as affected.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% points to a very low current exploitation likelihood. The issue is not included in the CISA KEV catalog. Attackers must entice a logged‑in user, typically an administrator, to visit a crafted URL; the CSRF attack then executes actions within the user’s authenticated session.
OpenCVE Enrichment