Impact
A CSRF vulnerability exists in the Fuelthemes Werkstatt WordPress theme versions 4.7.2 and earlier, allowing an attacker to trick an authenticated user into submitting a forged request that the site processes. The CVE states this is an unauthenticated CSRF, meaning the attacker does not need their own credentials to trigger the flaw; it relies on the victim’s logged‑in session. The exact actions that can be performed are not described, but any state‑changing request exposed by the vulnerable theme could potentially be executed without authorization.
Affected Systems
WordPress installations that employ the Fuelthemes Werkstatt theme with a version of 4.7.2 or earlier are impacted. Sites using a later release are not affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 4.3 indicating moderate severity, and an EPSS score of less than 1 %, suggesting a low likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog, implying no widespread known exploitation. Attackers can trigger the flaw by tricking a logged‑in administrator or other authenticated user into visiting a crafted URL or submitting a disguised form; no attacker credentials are required. Because the flaw permits the execution of state‑changing requests that the theme exposes, the impact could include unauthorized content modification, data tampering, or other privileged actions depending on the specifics of the exposed endpoints.
OpenCVE Enrichment