Impact
A vulnerability in the WorkScout-Core plugin allows a remote attacker to perform cross‑site request forgery that results in authentication bypass. The flaw enables the attacker to execute privileged actions without needing valid user credentials, directly compromising the confidentiality and integrity of the WordPress site.
Affected Systems
The affected product is the WordPress plugin WorkScout-Core by purethemes. All releases from the earliest available version up to and including 1.7.08 are affected. No other versions are listed as impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity weakness. The EPSS score of less than 1% shows a currently low exploitation probability, yet the vulnerability is still noteworthy. It is not listed in the CISA KEV catalog. The likely attack vector is a CSRF attack that an attacker can trigger through a malicious link or embedded content accessed by an authenticated user, granting the attacker unauthorized access.
OpenCVE Enrichment