Impact
A Cross‑Site Request Forgery vulnerability exists in the AA‑Team SearchAzon plugin for WordPress versions up to 1.4. The flaw allows an attacker to trick an authenticated user into submitting a request that the plugin processes, potentially changing settings or executing protected actions without the user’s consent. The weakness is identified as CWE‑352.
Affected Systems
The vulnerability affects all releases of the AA‑Team SearchAzon WordPress plugin from its earliest version through version 1.4. The product is installed in WordPress sites and performs Amazon product searches and listings.
Risk and Exploitability
The CVSS score is 4.3, signifying moderate severity, while the EPSS indicates a very low exploitation probability of less than 1%, and the vulnerability is not currently listed in the CISA KEV catalog. Based on the description, the likely attack vector involves a malicious webpage or email that contains a crafted URL or form submission to invoke the vulnerable action in a user’s browser, exploiting the lack of authentication or CSRF token verification.
OpenCVE Enrichment