Impact
The Copymatic – AI Content Writer & Generator plugin for WordPress contains a Cross‑Site Request Forgery flaw that bypasses nonce validation on the settings page. A forged request can alter the copymatic_apikey option without authentication, allowing an attacker to compromise the API key used for content generation. This vulnerability is identified as a CWE‑352 type flaw with a CVSS score of 4.3, indicating low‑to‑medium severity.
Affected Systems
All versions of the Copymatic – AI Content Writer & Generator plugin from ryanfaber up to and including 2.1 are affected. Administrators using these releases should verify the installed version and apply fixes when available.
Risk and Exploitability
The flaw offers a low‑probability attack vector that requires only an unauthenticated attacker to lure a site administrator into clicking a forged link. Because the EPSS score is below 1 % and the vulnerability is not listed in CISA's KEV catalog, the likelihood of widespread exploitation is currently low. Nonetheless, the potential to compromise the API key warrants prompt attention.
OpenCVE Enrichment
EUVD