Impact
The Galaxy Weblinks Post Featured Video plugin for WordPress has a CSRF flaw that allows an attacker to trigger any state‑changing request executed by the plugin while a user is logged in, without that user’s explicit consent. The vulnerability affects all releases up to and including version 1.7 and can lead to unintended modifications or actions that the victim is permitted to perform.
Affected Systems
Galaxy Weblinks – WordPress Post Featured Video plugin, all versions from the earliest release through 1.7.
Risk and Exploitability
The CVSS score of 4.3 ranks the issue as medium risk, while the EPSS score of less than 1% indicates that the flaw is currently unlikely to be actively exploited. The vulnerability is not listed in the CISA KEV catalog. Successful exploitation would require an authenticated user on the affected WordPress site and a malicious link or page that causes the user to submit a forged request targeting the plugin’s functionality. No public exploit has yet been reported.
OpenCVE Enrichment
EUVD