Impact
Unauthenticated Cross Site Request Forgery in the WordPress Photo Gallery by Supsystic plugin (versions 1.21.0 and earlier) allows an attacker to make the victim’s browser send privileged requests to the site without authentication. Because the plugin does not properly validate requests, a malicious actor can trigger state‑changing operations such as modifying gallery settings or exporting data, potentially compromising the integrity of the site. The impact is limited to the scope of the plugin’s capabilities but can lead to unauthorized changes that affect the content presented to site visitors.
Affected Systems
The vulnerability affects the WordPress Photo Gallery by Supsystic plugin versions up to and including 1.21.0. Any WordPress site that has one of these plugin versions installed is susceptible.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a cross‑site request forgery where an attacker crafts a request that the victim’s browser sends to the site, exploiting the plugin’s missing CSRF protection to execute privileged actions without requiring the victim to be authenticated.
OpenCVE Enrichment