Impact
WordPress sites that run the Mergado Pack plugin, version 4.2.1 or older, contain a CSRF defect that permits an attacker to cause an authenticated user to perform unintended actions without their consent. The flaw allows arbitrary requests to be executed in the user’s context, potentially modifying plugin settings or data managed by the plugin. This weakness is identified as CWE‑352, indicating an absence of proper validation of request origin.
Affected Systems
Any WordPress installation that has the MERGADO Mergado Pack plugin installed with a version of 4.2.1 or earlier is vulnerable. Administrators should verify the plugin version in the WordPress dashboard and compare it with the release note indicating the secure version.
Risk and Exploitability
The CVSS score of 4.3 places this issue in the medium severity range, indicating that the impact is noticeable but not catastrophic. The EPSS score is less than 1 %, pointing to a low probability of widespread exploitation at the moment. This vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is via a malicious URL or form that sends a forged request through the victim’s authenticated session, inferring that the attacker must first lure the user to click a link or submit a form.
OpenCVE Enrichment