Impact
The Social Photo Fetcher plugin contains a CSRF flaw that permits an attacker to cause a logged‑in administrator to perform unintended operations, such as altering plugin settings or initiating photo imports, without the administrator’s knowledge. The weakness is identified as CWE‑352 and introduces the risk of unauthorized modification of the site’s data or configuration.
Affected Systems
JK Social Photo Fetcher plugin for WordPress, versions up through 3.0.4, deployed on WordPress sites.
Risk and Exploitability
The vulnerability has a CVSS score of 4.3, indicating moderate severity, and an EPSS score of less than 1%, meaning exploitation probability is low. It is not listed in the CISA KEV catalog. The likely attack vector is a malicious webpage that lures an authenticated WordPress user with administrative privileges to visit, causing their browser to submit a forged request to the plugin’s endpoint. Successful exploitation could lead to unauthorized configuration changes or unintended content retrieval, affecting the integrity and availability of the site.
OpenCVE Enrichment