Impact
The Easy Flashcards plugin for WordPress contains a flaw where the nonce check on the ef_settings_submenu page is missing or implemented incorrectly. This allows an unauthenticated attacker to forge a client‑side request that updates the plugin’s settings. Because the new settings are rendered in the site’s output, a malicious script can be stored and executed in the browsers of all visitors, enabling defacement, credential theft, or further attack vectors.
Affected Systems
WordPress sites running the Easy Flashcards plugin version 0.1 or earlier are affected. The vulnerability is limited to the plugin’s settings page and does not directly compromise the core WordPress installation.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.1, indicating a moderate severity. The EPSS score is below 1 %, suggesting that exploitation is unlikely at present. The weakness is not listed in the CISA KEV catalog. An attacker can exploit this flaw by luring an administrator to click a crafted link or by sending a form request; the exploit requires no prior exploitation of other components and relies solely on the missing nonce validation to perform unauthorized changes.
OpenCVE Enrichment
EUVD