Impact
An unauthenticated cross‑site request forgery flaw exists in the Fuelthemes Werkstatt WordPress theme version 4.7 (CWE‑352). Because the theme’s endpoints do not verify a CSRF token, an attacker can trick a logged‑in WordPress user into submitting a forged request that the site treats as a legitimate action performed by that user. The flaw does not require the attacker to have any credentials or elevated privileges; it only relies on the victim’s authenticated session and the attacker’s ability to host a malicious page that triggers the vulnerable endpoint.
Affected Systems
WordPress installations that use the Fuelthemes Werkstatt theme 4.7.2 or earlier are impacted. Any logged‑in user—regardless of role—could be target of the attack when visiting a malicious site that sends a forged request to the theme’s vulnerable endpoint.
Risk and Exploitability
The CVSS score is 4.3, indicating a moderate level of risk. An EPSS score of less than 1% suggests the likelihood of exploitation is low but it remains a real threat. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a browser‑based CSRF that requires only a malicious web page to lure the user; no additional system or network access is required.
OpenCVE Enrichment