Impact
The SupportCandy plugin contains a Cross‑Site Request Forgery flaw (CWE‑352) that allows attackers to force authenticated users to submit plugin requests without proper validation, resulting in unintended actions and potential data alteration on the site.
Affected Systems
WordPress installations that use the PSM Plugins SupportCandy plugin version 3.4.1 or earlier are impacted; any release up to and including 3.4.1 is vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while an EPSS score of less than 1% signals a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user who is tricked into visiting a crafted URL or form that triggers the plugin’s unprotected action.
OpenCVE Enrichment