Impact
The DoFollow Case by Case WordPress plugin contains a CSRF flaw that permits attackers to trigger plugin actions without user consent. This could allow an attacker to modify the plugin’s settings or perform other unintended actions on the site, potentially compromising the site’s integrity.
Affected Systems
Apasionados DoFollow Case by Case plugin, version 3.5.1 or earlier, used within WordPress sites.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the low EPSS (<1%) suggests the probability of exploitation is low. It is not listed in CISA’s KEV catalog. The likely attack vector is inferred to be phishing or compromised site content, where a malicious link or embedded form forces a logged‑in user to submit a forged request. No known public exploit exists, but the flaw remains present in all versions up to 3.5.1.
OpenCVE Enrichment