Impact
An unauthenticated Cross Site Request Forgery vulnerability exists in WPIDE versions up to and including 3.5.6. Based on the description, it is inferred that an attacker can craft a request that a logged‑in user will automatically send from their browser while expecting to perform a legitimate action. Because the plugin lacks proper CSRF defenses, the attacker can trigger file access or modification operations without the user’s knowledge, potentially enabling arbitrary file reading, overwriting, or deletion on the WordPress installation. The failure is classified as CWE‑352, a cross‑site request forgery defect.
Affected Systems
Any WordPress site that has the XplodedThemes WPIDE – File Manager & Code Editor plugin installed in any configuration for versions up to and including 3.5.6 is affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating a high severity. The EPSS score is less than 1%, meaning the empirical probability of exploitation is very low, and the issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers would need to lure a logged‑in user to visit a malicious URL that submits the forged request, exploiting the lack of authentication checks on the plugin’s administrative actions.
OpenCVE Enrichment