Impact
A Cross‑Site Request Forgery vulnerability exists in the Zoho Flow WordPress plugin for versions up to 2.14.1. The vulnerability stems from missing or incorrect nonce validation in the zoho_flow_deactivate_plugin function. An attacker who can craft a forged request and trick a site administrator into clicking a link could change typography settings on a site, thereby tampering with the site’s visual presentation and possibly its user experience.
Affected Systems
The affected component is the Zoho Flow plugin for WordPress. Versions up to and including 2.14.1 are impacted. Administrators who have super‑user privileges to the WordPress site must be tricked into clicking a malicious link.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score is less than 1%, suggesting a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack likely requires a social engineering effort to get an administrator to click a malicious link, after which the attacker can modify typography settings without any further authentication.
OpenCVE Enrichment
EUVD