Impact
The vulnerability is a Cross‑Site Request Forgery (CSRF) flaw in the Saad Iqbal Post Snippets WordPress plugin. An attacker who successfully lures a logged‑in administrator or editor to a specially crafted URL could coerce the browser to execute unintended actions within the plugin’s context. While the flaw does not provide remote code execution, it can lead to unauthorized modification—or deletion—of post snippets, potentially undermining site integrity.
Affected Systems
Any WordPress installation that has the Post Snippets plugin (by Saad Iqbal) installed with a version equal to or older than 4.0.11 is affected. This includes sites using the latest deployment of the plugin before the 4.0.12 release.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk that mainly affects the integrity of the website. The EPSS score of <1% suggests that exploit attempts are unlikely to be widely observed. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an authenticated user’s browser to be tricked into submitting a malicious request, so the likelihood of successful attack is limited to users who visit a crafted link or are infected with malware that cooperates with the site.
OpenCVE Enrichment