Impact
WordPress plugin Theme My Login, version 7.1.14 and earlier, contains an unauthenticated CSRF vulnerability. An attacker can send a forged request that is processed by the plugin because it lacks adequate anti‑forgery protection. This enables the attacker to execute any action that the victim user is authorized to perform, potentially modifying settings or user data, without requiring direct authentication or knowledge of user credentials. The weakness is identified as CWE‑352 and carries a CVSS score of 4.3, reflecting moderate risk with limited impact compared to higher‑severity flaws.
Affected Systems
The affected product is the WordPress plugin "Theme My Login" developed by Jeff Farthing. All releases up to and including version 7.1.14 are vulnerable; any site that has installed this plugin without updating beyond that release is at risk.
Risk and Exploitability
The CVSS score indicates moderate severity, and the EPSS score is unavailable, suggesting no current evidence of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog, further implying limited or no widespread exploitation. Attackers can exploit the flaw from any location by crafting a malicious web page that sends a request to the vulnerable WordPress instance; no prior authentication is required. The attack vector is inferred as a cross‑site HTTP request that the plugin processes without verifying a CSRF token.
OpenCVE Enrichment