Impact
The vulnerability is a CSRF flaw in the Vehica Core WordPress plugin that allows an attacker to trick authenticated users into performing unwanted actions without their consent. This flaw can lead to unauthorized changes in the site, such as altering settings or publishing content, compromising the integrity of the website.
Affected Systems
The issue affects the Vehica Core WordPress plugin from TangibleWP, for all versions up to and including 1.0.100.
Risk and Exploitability
The CVSS score of 4.3 suggests moderate severity, while the EPSS score of less than 1% indicates low probability of exploitation during the analysis period. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers would likely need a victim who is logged into the site and could be presented with a crafted URL or form (the likely attack vector) to trigger the flaw.
OpenCVE Enrichment
EUVD