Impact
The vulnerability is a CSRF flaw that allows an attacker to trigger form actions on a WordPress site running the FormFacade plugin by forging a request from the victim's browser. This can result in unauthorized form submissions or other side effects that the form is designed to perform, effectively giving the attacker the privileges of a logged‑in user.
Affected Systems
WordPress installations that have the FormFacade plugin version 1.4.1 or earlier. The plugin is distributed by the author manidoraisamy under the name FormFacade.
Risk and Exploitability
With a CVSS score of 4.3 the flaw is considered moderate; the EPSS score indicates a very low probability of exploitation in the current environment. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to convince a legitimate user to visit a crafted link or submit a form, so the attack vector is web‑based and requires victim interaction. No public exploit is known, but the low EPSS and moderate score suggest that the risk is limited unless the site relies heavily on the plugin or user actions are sensitive.
OpenCVE Enrichment