Impact
The flaw is a Cross‑Site Request Forgery vulnerability in the WordPress plugin hamsalam – همگام سازی ووکامرس و باسلام sync‑basalam. The plugin accepts requests without verifying the request origin, allowing an attacker to cause a victim’s authenticated browser to perform privileged actions such as changing plugin settings or triggering orders. This weakness is classified as CWE‑352, reflecting the absence of proper request intent validation.
Affected Systems
The vulnerability affects the hamsalam – همگام سازی ووکامرس و باسلام sync‑basalam WordPress plugin versions from the initial release through 1.9.1. No specific sub‑version breakpoints are listed, so all releases up to and including 1.9.1 are considered vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, but the EPSS score of less than 1% suggests that widespread exploitation is currently unlikely. The flaw is not listed in the CISA KEV catalog. The likely attack vector is remote; an attacker can craft a malicious link or hidden form that, when visited by a logged‑in user, sends a forged request to the site. Successful exploitation would allow the attacker to execute any operation that the victim’s credentials permit, potentially leading to data exposure or site compromise.
OpenCVE Enrichment