Impact
An unauthenticated Cross Site Request Forgery vulnerability exists in versions of the WordPress Popup for CF7 with Sweet Alert plugin up to 1.6.5. The flaw allows an attacker to forge a request that is accepted by the plugin without requiring authentication, potentially modifying site content or triggering form submissions. This is a classic CSRF (CWE-352).
Affected Systems
WordPress sites that have installed the Popup for CF7 with Sweet Alert plugin version 1.6.5 or earlier, authored by Metin Saraç. No specific WordPress version restriction is listed, so any site running these plugin versions is affected.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score is below 1%, suggesting a very low but non-zero exploitation probability. The vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that an attacker can send a forged request without authentication, so the attack vector is web-based CSRF.
OpenCVE Enrichment