Impact
Unauthenticated Cross Site Request Forgery is a flaw that allows an attacker to send forged requests from a victim’s browser, causing the site to execute privileged actions as if performed by the victim. Based on the description, it is inferred that the weakness (CWE‑352) means the attacker needs no direct credentials: it merely exploits a browser already logged into the site. Based on the description, it is inferred that an attacker could potentially alter content, change settings, or execute destructive actions that the victim’s role permits.
Affected Systems
All WordPress installations that use the Avada Core plugin from Avada Studio up to and including version 5.15.6.
Risk and Exploitability
The CVSS score of 9.6 indicates a very high impact even though the EPSS score is less than 1%, suggesting that targeted exploitation may be rare at present. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that exploitation requires only a crafted URL or form that the victim’s browser will submit, making the attack vector purely web‑based with no need for attacker authentication.
OpenCVE Enrichment