Impact
The vulnerability is an unauthenticated Cross Site Request Forgery flaw in versions of the Plugins Garbage Collector (Database Cleanup) plugin for WordPress up to 0.14. It allows an attacker to submit crafted requests that the plugin will accept without verifying the requestor’s intent, enabling the execution of cleanup actions or deletion of database entries. Because the plugin does not validate a CSRF token, a malicious site or phishing message can force a victim’s browser to send a request on the victim’s behalf while the victim is logged in, potentially compromising the integrity of the site’s database.
Affected Systems
The affected product is the WordPress plugin named Plugins Garbage Collector (Database Cleanup) published by Vladimir Garagulya. All releases of the plugin with a version number of 0.14 or lower are vulnerable. WordPress sites that have installed any of these versions are at risk.
Risk and Exploitability
The CVSS score for this vulnerability is 6.5, indicating a medium level of severity. The EPSS score is not available, so the current exploitation probability is unknown; however, the lack of CSRF checks means the flaw could be easily abused by an attacker. The vulnerability is not yet listed in the CISA KEV catalog, so no known exploits have been publicly reported.
OpenCVE Enrichment