Impact
Modular DS: Monitor, update, and backup multiple websites is vulnerable to Cross‑Site Request Forgery in all versions up to and including 2.5.1. The vulnerability arises from missing nonce validation in the postConfirmOauth() function, which permits an attacker to forge a request that disconnects the plugin’s OAuth/SSO connection when a site administrator submits it. This type of flaw allows an unauthenticated attacker to alter a privileged configuration setting, effectively disabling single sign‑on functionality without credentials. The weakness corresponds to CWE‑352.
Affected Systems
The affected product is modulards:Modular DS: Monitor, update, and backup multiple websites. All versions up to 2.5.1 are impacted; newer releases are presumed fixed. Administrators using the plugin at any of these versions are at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium impact and an attack vector that requires interaction with a privileged user. The EPSS score is less than 1 %, suggesting a low probability of automated exploitation today. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker to lure an administrator into unknowingly submitting a crafted request, such as clicking a malicious link or visiting a malicious page while logged in.
OpenCVE Enrichment