Impact
The vulnerability is a Cross‑Site Request Forgery flaw that allows an attacker to force an authenticated user of the ProteusThemes Custom Sidebars plugin to send unauthorized requests. This could lead to unintended changes or actions performed on the site, compromising the integrity of the WordPress installation. The weakness is identified as CWE‑352 and is a typical CSRF vulnerability.
Affected Systems
The issue affects the ProteusThemes Custom Sidebars by ProteusThemes WordPress plugin. All installations running version 1.0.3 or earlier are affected, including any version where the release date is unknown but falls within the n/a through <= 1.0.3 range.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity with moderate impact. The EPSS score is less than 1 %, suggesting a very low but non‑zero likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further indicating limited known exploitation. Attackers could exploit this by sending crafted requests from a malicious site to the victim’s browser, relying on the victim’s logged‑in session to perform unintended actions.
OpenCVE Enrichment