Impact
The vulnerability is a CSRF flaw that allows an attacker to trick authenticated users into unknowingly submitting requests that can modify or delete content within the WordPress site. By sending a crafted link or form, the attacker can perform actions that the logged‑in user would normally authorize, thereby potentially altering blog posts or pages. The flaw specifically affects the Simple Content Templates for Blog Posts & Pages plugin from Clifton Griffin, versions up to and including 2.2.61.
Affected Systems
WordPress sites using the Simple Content Templates for Blog Posts & Pages plugin from the Clifton Griffin developer, with versions 2.2.61 or earlier are susceptible.
Risk and Exploitability
The CVSS score of 4.3 indicates a low severity, and the EPSS score of less than 1% suggests a very low probability of exploitation in the near term. The vulnerability is not currently listed in CISA’s KEV catalog. Attackers would need the victim to be authenticated to the site and might lure them with a malicious link or embedded form, exploiting the lack of CSRF protection in the plugin. The risk is therefore limited to users who remain logged in and the site’s recovery requires addressing the plugin.
OpenCVE Enrichment