Impact
This vulnerability is a Cross‐Site Request Forgery flaw in the FanBridge signup plugin for WordPress. An attacker can craft a URL that triggers a request automatically executed by a logged‑in administrator, allowing the attacker to perform any action that the authenticated user is authorized to do. In some configurations the plugin may also store malicious XSS payloads, potentially compromising the content rendered to site visitors.
Affected Systems
The issue affects the FanBridge signup plugin on WordPress sites running any version up to and including 0.6.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, but the EPSS score of less than 1% suggests exploitation is currently rare. Attackers must use a victim who is logged into the site with sufficient privileges and lure the victim to a malicious link; the exploit does not rely on external network access and is not listed in the CISA KEV catalog.
OpenCVE Enrichment