Impact
The vulnerability is a Cross‑Site Request Forgery flaw in the Live Shopping & Shoppable Videos For WooCommerce plugin, allowing an attacker to forge requests that are executed with the privileges of the authenticated WordPress user. This can lead to unauthorized changes or actions performed on the website but does not directly provide code execution. The weakness is identified as CWE‑352.
Affected Systems
Channelize.io Team Live Shopping & Shoppable Videos For WooCommerce live‑shopping-video-streams plugin versions n/a through 2.2.0 are affected. Hosts running any of these versions are vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate overall risk. The EPSS score of <1% shows a very low likelihood of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is a malicious webpage that tricks a logged‑in user into visiting a URL that triggers an unwanted request to the WordPress site.
OpenCVE Enrichment