Impact
The vulnerability is a Cross‑Site Request Forgery flaw that allows any visitor to send a forged request to the Slider by 10Web plugin without authentication. The flaw permits deletion of arbitrary files on the web server, which can lead to loss of data, defacement, or loss of service availability for the affected WordPress site. The weakness is identified as CWE‑352 and manifests as insufficient CSRF protection in request handling logic.
Affected Systems
The defect exists in the 10Web:Slider by 10Web WordPress plugin for all releases up to and including version 1.2.62. No additional or patched versions are mentioned in the supplied data.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity. Because authentication is not required, any visitor can trigger the exploit, dramatically increasing risk. No EPSS data is available, but the lack of an authentication barrier and the potential for complete file deletion make this vulnerability highly dangerous. It is not listed in CISA’s KEV catalog, but administrators should treat it as a significant business risk.
OpenCVE Enrichment