Impact
The vulnerability is a Cross‑Site Request Forgery flaw in the NewsExo WordPress theme that allows an attacker to make authenticated users perform actions without their consent. The flaw is identified as CWE‑352 and does not provide direct code execution or data disclosure. An attacker could potentially trigger unauthorized changes to content, settings, or other actions that the user is permitted to carry out.
Affected Systems
All installations of the NewsExo theme bundled by themearile with a version number up to 7.1 are affected. Site owners who have not upgraded beyond this version remain susceptible.
Risk and Exploitability
The CVSS score of 4.3 indicates a low‑to‑moderate severity, and the EPSS score of less than 1 % suggests a low chance of widespread exploitation. The flaw is not listed in CISA's KEV catalog. The attack likely requires a user with an active authenticated session; a malicious site could embed a request that triggers the action, making the exploit feasible through normal web interactions.
OpenCVE Enrichment