Impact
The vulnerability is an unauthenticated Cross‑Site Request Forgery (CWE‑352) affecting the ApusListing theme up to version 1.2.63. An attacker can induce an already‑logged‑in user to submit a crafted request, causing the site to perform privileged actions under that user's identity.
Affected Systems
All WordPress installations that use the ApusTheme ApusListing theme with versions 1.2.63 or earlier are impacted. The patch is available in version 1.2.64 and later, which removes the vulnerable code path. No further product or vendor extensions are mentioned in the data.
Risk and Exploitability
The CVSS score of 8.8 places this flaw in the Severe category, while the EPSS score of less than 1% indicates a low but non‑zero current exploitation probability. Because the attack vector is web‑based and requires only that a legitimate user be tricked into visiting a crafted request, it is feasible for opportunistic attackers. It is not listed in the CISA KEV catalog, so no mass exploitation indicators are reported yet.
OpenCVE Enrichment