Impact
A Cross‑Site Request Forgery (CSRF) vulnerability in the Saad Iqbal WP EasyPay plugin allows attackers to perform actions that require an authenticated WordPress session. The plugin’s lack of robust request validation can enable unintended state changes, though the precise impact depends on the plugin’s exposed functionality. This flaw is present in all versions up to 4.5.0.
Affected Systems
All releases of the WP EasyPay plugin from Saad Iqbal up to and including version 4.5.0 are impacted. The vulnerability exists in all publicly available builds within that range, and no specific configuration or patch level is detailed beyond the version limit.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. An EPSS score of less than 1% signals a very low current exploitation probability. The flaw is not listed in the CISA KEV catalog. The likely attack scenario, inferred from the nature of CSRF, requires a victim who is authenticated to the WordPress site to be induced to submit a malicious request to the plugin’s endpoints, such as via a link or form embedded in a third‑party page.
OpenCVE Enrichment