Impact
There is a Cross‑Site Request Forgery (CSRF) flaw in the teachPress WordPress plugin up to and including version 9.0.12. The flaw allows malicious sites or links to force a logged‑in user to send requests to the plugin’s endpoints without proper verification, potentially causing unintended changes to the site content or plugin configuration and compromising the integrity of the site.
Affected Systems
The vulnerability affects the teachPress plugin developed by winkm89. All installations of teachPress from any unspecified version through 9.0.12 are impacted. Users should check that they are not running any of these versions.
Risk and Exploitability
The CVSS score is 5.4, indicating a moderate severity. The EPSS score is less than 1%, suggesting low likelihood of exploitation; furthermore, the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. The likely attack vector is a browser‑based interaction where an attacker lures an administrator to a crafted link or form that issues a request to the teachPress endpoint without proper CSRF validation.
OpenCVE Enrichment